Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 28 Jul 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Scottpaterson
Scottpaterson contact Form 7 – Paypal & Stripe Add-on Wordpress Wordpress wordpress |
|
| Vendors & Products |
Scottpaterson
Scottpaterson contact Form 7 – Paypal & Stripe Add-on Wordpress Wordpress wordpress |
Mon, 27 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-601 | |
| Metrics |
cvssV3_1
|
Mon, 27 Jul 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow. | |
| Title | Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-27T17:29:31.136Z
Reserved: 2026-06-30T12:57:33.276Z
Link: CVE-2026-14236
Updated: 2026-07-27T17:25:36.728Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-28T20:38:42Z