SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14236

MEDIUM · CVSS 4.7 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The Contact Form 7 plugin for WordPress prior to version 2.5 is vulnerable due to inadequate validation of user-supplied return URLs, which can be exploited by unauthenticated attackers to redirect users to arbitrary external sites post-checkout. This could lead to phishing attacks or other malicious activities targeting users. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk.

CVE
CVE-2026-14236
Severity
MEDIUM
CVSS
4.7
EPSS
0.17%
WordPress

Original NVD Description

The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow.