CyberRota
← Ana sayfaya dön

CVE-2026-14236

UNKNOWN · CVSS N/A

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-27T07:16:25.797 · Çekilme zamanı: 2026-07-27T12:09:40.335151+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-14236
Severity
UNKNOWN
CVSS
N/A
EPSS
Yok
WordPress

Orijinal NVD Açıklaması

The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow.