Executive brief
The Coinbase Commerce for Contact Form 7 plugin for WordPress, which allows websites to accept cryptocurrency payments through contact forms, contains a security flaw. This vulnerability allows any logged-in user, even those with low-level permissions like subscribers, to change the site's Coinbase API key. If exploited, an attacker could redirect payments to their own account or disrupt the site's ability to process transactions.
Technical details
The vulnerability is classified as Missing Authorization (CWE-862) within the save_settings() function of the Coinbase Commerce for Contact Form 7 plugin. The function, which is hooked to admin_post_cccf7_save_settings, fails to perform a capability check (e.g., current_user_can()) or verify a security nonce. Consequently, an authenticated attacker with Subscriber-level permissions or higher can send a crafted POST request to /wp-admin/admin-post.php to overwrite the 'cccf7_api_key' option in the WordPress database. This can lead to the redirection of cryptocurrency payments or a denial of service for payment processing.
Affected products
- Coinbase Commerce for Contact Form 7 Project Coinbase Commerce for Contact Form 7 up to and including 1.1.2
Timeline
- 2026-05-12: disclosed: Vulnerability published to NVD and Wordfence.
References
- https://plugins.trac.wordpress.org/browser/coinbase-commerce-for-contact-form-7/tags/1.1.2/includes/class-admin-settings.php
- https://plugins.trac.wordpress.org/browser/coinbase-commerce-for-contact-form-7/tags/1.1.2/includes/class-admin-settings.php
- https://plugins.trac.wordpress.org/browser/coinbase-commerce-for-contact-form-7/tags/1.1.2/includes/class-admin-settings.php
- https://plugins.trac.wordpress.org/browser/coinbase-commerce-for-contact-form-7/trunk/includes/class-admin-settings.php
- https://plugins.trac.wordpress.org/browser/coinbase-commerce-for-contact-form-7/trunk/includes/class-admin-settings.php
- https://plugins.trac.wordpress.org/browser/coinbase-commerce-for-contact-form-7/trunk/includes/class-admin-settings.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/9bff2532-802c-4bb1-a0a2-7f5f928deb23?source=cve