Sceawere

Vulnerability Detail

CVE-2026-105990UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Data Export Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
8h ago
Vendor
Unknown
Product
Accept PayPal Payments using Contact Form 7
Attack Type
CWE-200 Information Exposure
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization checks before exporting stored form submissions, allowing unauthenticated attackers to download the personal data (name, email, telephone, postal address, message) and payment metadata of everyone who submitted a payment form.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-10T06:16:40.677Z",
  "pubdate": "2026-10-10T06:16:40.677Z",
  "executiveSummary": "The Accept PayPal Payments using Contact Form 7 WordPress plugin is affected by an unauthorized data export vulnerability. This flaw arises from a failure to implement proper access control mechanisms for the plugin's submission export functionality.\nThe vulnerability allows unauthenticated remote attackers to bypass authorization checks and extract sensitive data associated with form submissions. Impacted information includes personal identifiable information (PII), such as names, email addresses, telephone numbers, and postal addresses, alongside sensitive payment metadata.\nThis represents a critical security risk as it facilitates mass exfiltration of user data without requiring prior authentication or administrative privileges. Affected products include the Accept PayPal Payments using Contact Form 7 WordPress plugin versions prior to 4.0.7.\nThe attack vector is network-based and can be executed by any remote actor with access to the target web application. Organizations using this plugin version are at significant risk of data privacy breaches, regulatory non-compliance, and reputational damage.",
  "technicalDetails": "The core vulnerability is identified as a Broken Access Control issue within the Accept PayPal Payments using Contact Form 7 plugin's submission management component. The plugin failed to validate the requester's session, roles, or capabilities before executing functions responsible for exporting stored form submissions.\nThe attack vector involves a direct request to the export functionality of the plugin. Because the plugin does not enforce authentication, an attacker can trigger the export process by sending an unauthenticated HTTP request to the corresponding endpoint. The server-side code, lacking authorization logic, proceeds to retrieve stored submission records from the database and compiles them into an exportable format for the attacker.\nThe exploit flow is straightforward: 1) The attacker identifies the publicly accessible export endpoint managed by the plugin. 2) The attacker crafts an HTTP request targeting this endpoint without supplying any valid session tokens or authentication headers. 3) The application’s backend processes the request and fails to verify if the user possesses the required administrative privileges to view or export submission data. 4) The plugin generates a file containing sensitive submission records and metadata, transmitting this sensitive data directly back to the attacker's browser.\nThe vulnerable component is the submission management module, which handles the retrieval and serialization of user-submitted payment form data. Since the plugin fails to implement 'current_user_can()' checks or similar WordPress permission validation mechanisms, the system treats unauthenticated requests with the same authority as legitimate administrative requests.\nAffected versions include all iterations of the plugin prior to 4.0.7. The impact is significant, leading to the unauthorized disclosure of full user profiles captured through payment forms, including sensitive payment metadata which could be used for further malicious activities such as targeted phishing or financial fraud. There are no requirements for specialized knowledge or complex exploit chains; the vulnerability is accessible through standard web traffic, making it highly susceptible to automated scraping tools."
}
CVE-2026-105990: Unauthenticated Data Export Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere