AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66660

MEDIUM · CVSS 6.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Contact Form 7 – PayPal & Stripe Add-on versions up to 2.5.1 are vulnerable to unauthenticated broken access control, allowing attackers to exploit the add-on without authentication. This could lead to unauthorized access to sensitive data or functionality, potentially compromising user information and payment processes. Organizations using these versions of the add-on should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-66660
Severity
MEDIUM
CVSS
6.5
EPSS
0.24%

Original NVD Description

Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions.