Extension WordPress

Vulnérabilités Contact Form 7 – PayPal & Stripe Add-on

Cette page rassemble les failles publiées pour Contact Form 7 – PayPal & Stripe Add-on, leurs plages de versions affectées et les correctifs signalés dans la base locale.

7Vulnérabilités
0Critiques
7Avec correctif
6,1CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Contact Form 7 – PayPal & Stripe Add-on

7 fiches

CVE-2026-9189 Moyenne · 5,3
Contact Form 7 – PayPal & Stripe Add-on

Contact Form 7 – PayPal & Stripe Add-on <= 2.4.9 – Unauthenticated Payment Bypass via Insufficient Verification of Data Authenticity via PayPal IPN Handler ('invoice'/'mc_gross' Verification)

The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all versions up to, and including, 2.4.9. Although `cf7pp_paypal_ipn_handler()` correctly validates IPN authenticity by…

Versions affectées

*-2.4.9

Correctif

2.4.10

Publication

28/05/2026

CVE-2025-47518 Moyenne · 4,4
Contact Form 7 – PayPal & Stripe Add-on

Contact Form 7 – PayPal & Stripe Add-on <= 2.3.4 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-2.3.4

Correctif

2.4.1

Publication

07/05/2025

CVE-2024-1719 Moyenne · 4,3
Contact Form 7 – PayPal & Stripe Add-on

Easy PayPal & Stripe Buy Now Button <= 1.8.3 & Contact Form 7 – PayPal & Stripe Add-on <= 2.1 – Cross-Site Request Forgery to Settings Update

The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.3 and in Contact Form 7 – PayPal & Stripe Add-on all versions up…

Versions affectées

*-2.1

Correctif

2.2

Publication

27/02/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités