Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105990— Accept PayPal Payments Using Contact Form 7 < 4.0.7 - Unauthenticated PII Disclosure via CSV Export

Quick assessment

Affected
Unknown Accept PayPal Payments using Contact Form 7
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Contact Form 7 的“接受 PayPal 付款”插件(版本低于 4.0.7)中,在导出已存储的表单提交内容之前,未执行任何授权检查。这使得未经身份验证的攻击者能够下载所有提交过付款表单的用户的个人数据(包括姓名、电子邮件、电话、邮寄地址和消息内容)以及支付元数据。

AI Predicted 9.1 Difficulty: Trivial EPSS 0.16% · P4

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage

Affected Version Matrix 1

VendorProduct Version RangeStatus
Unknown Accept PayPal Payments using Contact Form 7 < 4.0.7 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105990

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Accept PayPal Payments Using Contact Form 7 < 4.0.7 - Unauthenticated PII Disclosure via CSV Export
Source: CVE Program / CVE List V5
Vulnerability Description
The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization checks before exporting stored form submissions, allowing unauthenticated attackers to download the personal data (name, email, telephone, postal address, message) and payment metadata of everyone who submitted a payment form.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown Accept PayPal Payments using Contact Form 7 0 ~ 4.0.7 -

II. Public POCs for CVE-2026-105990

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105990

请登录查看更多情报信息。

Other References for CVE-2026-105990 (1)

Same Patch Batch · Unknown · 2026-10-10 · 16 CVEs total

CVE-2026-94256 SMS Alert 4.0.0 - Unauthenticated Authentication Bypass via Login with OTP
CVE-2026-94257 SMS Alert 3.9.6 - 4.0.0 - Unauthenticated Privilege Escalation via Arbitrary Password Rese
CVE-2026-87780 LTL Freight Quotes – Old Dominion Edition < 4.2.19 - Unauthenticated Stored XSS via Shippi
CVE-2026-87781 LTL Freight Quotes – Old Dominion Edition 4.2.11 - 4.2.18 - Unauthenticated SQLi via Shipp
CVE-2026-85571 Tutor LMS 4.0.5 - 4.1.0 - Instructor+ Arbitrary Post Reparenting via IDOR
CVE-2026-105995 Booking Package < 1.7.30 - Unauthenticated Booking Customer PII Disclosure
CVE-2026-107321 W3 Total Cache < 2.10.6 - Author+ Path Traversal via CDN Media Library Import
CVE-2026-107120 Contest Gallery < 33.0.1 - Unauthenticated Email Verification Bypass via Brute-Forceable R
CVE-2026-107323 Gallery PhotoBlocks 1.3.5 - Contributor+ Stored XSS
CVE-2026-105976 Portfolio Filter Gallery < 2.2.1 - Contributor+ Missing Authorization via Multiple AJAX Ac
CVE-2026-105989 Accept PayPal Payments using Contact Form 7 < 4.0.7 - Unauthenticated Transaction Status F
CVE-2026-105977 Portfolio Filter Gallery 2.0.2 - 2.2.0 - Contributor+ Cross-User Video Thumbnail Deletion
CVE-2026-104754 Rank Math SEO < 1.0.280 - Admin+ Stored XSS via Redirection Source URL
CVE-2026-104752 Rank Math SEO < 1.0.280 - Admin+ Arbitrary File Upload to RCE via Settings Import
CVE-2026-104753 Rank Math SEO < 1.0.280 - Admin+ SQLi via 'per_page' Parameter

IV. Related Vulnerabilities

V. Comments for CVE-2026-105990

No comments yet


Leave a comment