Extension WordPress
Vulnérabilités Contact Form 7 – PayPal & Stripe Add-on
Cette page rassemble les failles publiées pour Contact Form 7 – PayPal & Stripe Add-on, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Contact Form 7 – PayPal & Stripe Add-on
7 fiches
Contact Form 7 – PayPal & Stripe Add-on <= 2.4.9 – Unauthenticated Payment Bypass via Insufficient Verification of Data Authenticity via PayPal IPN Handler ('invoice'/'mc_gross' Verification)
The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all versions up to, and including, 2.4.9. Although `cf7pp_paypal_ipn_handler()` correctly validates IPN authenticity by…
*-2.4.9
2.4.10
28/05/2026
Contact Form 7 – PayPal & Stripe Add-on <= 2.3.4 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping. This makes it possible for…
*-2.3.4
2.4.1
07/05/2025
Contact Form 7 – PayPal & Stripe Add-on <= 2.3.1 – Reflected Cross-Site Scripting
The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and…
*-2.3.1
2.3.2
08/11/2024
Contact Form 7 – PayPal & Stripe Add-on <= 2.3 – Reflected Cross-Site Scripting
The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.3 due to insufficient input sanitization and output escaping. This makes it possible for…
*-2.3
2.3.1
08/10/2024
Contact Form 7 – PayPal & Stripe Add-on <= 2.0 – Reflected Cross-Site Scripting
The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for…
*-2.0
2.1
16/03/2024
Easy PayPal & Stripe Buy Now Button <= 1.8.3 & Contact Form 7 – PayPal & Stripe Add-on <= 2.1 – Cross-Site Request Forgery to Settings Update
The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.3 and in Contact Form 7 – PayPal & Stripe Add-on all versions up…
*-2.1
2.2
27/02/2024
Contact Form 7 – PayPal & Stripe Add-on <= 1.9.3 – Cross-Site Request Forgery
The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.3. This is due to missing or incorrect nonce validation on one of its…
*-1.9.3
1.9.4
17/03/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.