PatchSiren

ZealousWeb CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ZealousWeb CVE published 2026-04-08

CVE-2026-39707

A Missing Authorization vulnerability was found in Accept PayPal Payments using Contact Form 7, a WordPress plugin. This issue allows for Exploiting Incorrectly Configured Access Control Security Levels and has a CVSS score of 5.3, classified as MEDIUM. The vulnerability affects versions from n/a through 4.0.4 of the plugin. Users should review and update their installations accordingly.