Junglewise Threat Intelligence

CVE-2026-39707: ZealousWeb Accept PayPal Payments using Contact Form 7 missing authorization

CVE-2026-39707 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

A vulnerability exists in the ZealousWeb 'Accept PayPal Payments using Contact Form 7' WordPress plugin, which is used to integrate PayPal payment processing into website contact forms. Due to missing authorization checks, an unauthorized user may be able to perform actions or access settings that should be restricted to administrators. This could lead to unauthorized changes in how payments are handled or configured on the site.

Technical details

A Missing Authorization (CWE-862) vulnerability exists in the ZealousWeb Accept PayPal Payments using Contact Form 7 plugin (contact-form-7-paypal-extension) through version 4.0.4 (or 4.0.6 according to some sources). The flaw stems from incorrectly configured access control security levels, where the plugin fails to properly validate user permissions before executing certain functions. An unauthenticated remote attacker can exploit this to perform actions that should require higher privileges. While the CVSS score is 5.3 (Medium), the impact is primarily limited to integrity (I:L) as it allows for unauthorized modifications rather than data theft or service disruption. No official patch has been confirmed in the provided advisory materials.

Affected products

  • ZealousWeb Accept PayPal Payments using Contact Form 7 <= 4.0.4 (NVD); <= 4.0.6 (Patchstack)

Timeline

  • 2026-01-30: other: Vulnerability reported by Nabil Irawan
  • 2026-03-01: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published to NVD

References