PatchSiren cyber security CVE debrief
CVE-2026-105989 Accept PayPal Payments using Contact Form 7 CVE debrief
The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization or request-validation checks on one of its AJAX actions, allowing unauthenticated attackers to forge the stored transaction status of records and to write the Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7's status metadata onto arbitrary posts.
- Vendor
- Accept PayPal Payments using Contact Form 7
- Product
- Accept PayPal Payments using Contact Form 7
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for WordPress installations with the Accept PayPal Payments using Contact Form 7 plugin should assess exposure and prioritize verification and remediation due to potential transaction status forgery and unauthorized metadata changes. Defenders should review AJAX actions and restrict access to prevent exploitation. Security teams and vulnerability management teams should also review and monitor for potential transaction status forgery.
Why it matters
Defenders should prioritize verifying the version of the Accept PayPal Payments using Contact Form 7 plugin and applying the necessary updates to prevent potential transaction status forgery. This vulnerability allows unauthenticated attackers to forge transaction status and write metadata onto arbitrary posts, which could lead to unauthorized changes and potential security risks.
- Potential transaction status forgery
- Unauthenticated access to AJAX actions
- Metadata modification on arbitrary posts
Technical summary
The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization or request-validation checks on one of its AJAX actions, allowing unauthenticated attackers to forge the stored transaction status of records and to write the Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7's status metadata onto arbitrary posts. This vulnerability allows for potential transaction status forgery and unauthorized changes to metadata on arbitrary posts, highlighting the need for defenders to prioritize verification and remediation.
Defensive priority
Defenders should prioritize verifying the version of the Accept PayPal Payments using Contact Form 7 plugin and applying the necessary updates to prevent potential transaction status forgery.
Recommended defensive actions
- Verify the version of the Accept PayPal Payments using Contact Form 7 plugin and apply updates to 4.0.7 or later
- Review and restrict access to AJAX actions in the plugin
- Monitor for potential transaction status forgery attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, but limited information is available on potential exploitation or affected systems. Defenders should verify the Accept PayPal Payments using Contact Form 7 plugin version and review AJAX actions for potential exposure. Limited evidence suggests unauthenticated attackers can forge transaction status and write metadata onto arbitrary posts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105989 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105989
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105989 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105989
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Accept PayPal Payments using Contact Form 7 < 4.0.7 - Unauthenticated Transaction Status Forgery
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105989.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/df2b15dd-1748-4dcf-8b4f-8c053dc0dd73/
Supplemental source - exploit, vdb-entry, technical-description
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.