The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 28 Jul 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Scottpaterson
Scottpaterson contact Form 7 – Paypal & Stripe Add-on Wordpress Wordpress wordpress |
|
| Vendors & Products |
Scottpaterson
Scottpaterson contact Form 7 – Paypal & Stripe Add-on Wordpress Wordpress wordpress |
Mon, 27 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-601 | |
| Metrics |
cvssV3_1
|
Mon, 27 Jul 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow. | |
| Title | Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-27T17:29:31.136Z
Reserved: 2026-06-30T12:57:33.276Z
Link: CVE-2026-14236
Updated: 2026-07-27T17:25:36.728Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-28T20:38:42Z
Weaknesses