在 Contact Form 7 的“接受 PayPal 付款”插件(版本低于 4.0.7)中,在导出已存储的表单提交内容之前,未执行任何授权检查。这使得未经身份验证的攻击者能够下载所有提交过付款表单的用户的个人数据(包括姓名、电子邮件、电话、邮寄地址和消息内容)以及支付元数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Accept PayPal Payments using Contact Form 7 | < 4.0.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Accept PayPal Payments using Contact Form 7 | 0 ~ 4.0.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94256 | SMS Alert 4.0.0 - Unauthenticated Authentication Bypass via Login with OTP | |
| CVE-2026-94257 | SMS Alert 3.9.6 - 4.0.0 - Unauthenticated Privilege Escalation via Arbitrary Password Rese | |
| CVE-2026-87780 | LTL Freight Quotes – Old Dominion Edition < 4.2.19 - Unauthenticated Stored XSS via Shippi | |
| CVE-2026-87781 | LTL Freight Quotes – Old Dominion Edition 4.2.11 - 4.2.18 - Unauthenticated SQLi via Shipp | |
| CVE-2026-85571 | Tutor LMS 4.0.5 - 4.1.0 - Instructor+ Arbitrary Post Reparenting via IDOR | |
| CVE-2026-105995 | Booking Package < 1.7.30 - Unauthenticated Booking Customer PII Disclosure | |
| CVE-2026-107321 | W3 Total Cache < 2.10.6 - Author+ Path Traversal via CDN Media Library Import | |
| CVE-2026-107120 | Contest Gallery < 33.0.1 - Unauthenticated Email Verification Bypass via Brute-Forceable R | |
| CVE-2026-107323 | Gallery PhotoBlocks 1.3.5 - Contributor+ Stored XSS | |
| CVE-2026-105976 | Portfolio Filter Gallery < 2.2.1 - Contributor+ Missing Authorization via Multiple AJAX Ac | |
| CVE-2026-105989 | Accept PayPal Payments using Contact Form 7 < 4.0.7 - Unauthenticated Transaction Status F | |
| CVE-2026-105977 | Portfolio Filter Gallery 2.0.2 - 2.2.0 - Contributor+ Cross-User Video Thumbnail Deletion | |
| CVE-2026-104754 | Rank Math SEO < 1.0.280 - Admin+ Stored XSS via Redirection Source URL | |
| CVE-2026-104752 | Rank Math SEO < 1.0.280 - Admin+ Arbitrary File Upload to RCE via Settings Import | |
| CVE-2026-104753 | Rank Math SEO < 1.0.280 - Admin+ SQLi via 'per_page' Parameter |
No comments yet