Rock Lobster, LLC Contact Form 5.9.5 for WordPress

CPE Details

Rock Lobster, LLC Contact Form 5.9.5 for WordPress
5.9.5
2024-07-01
16h30 +00:00
2024-07-01
16h30 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:rocklobster:contact_form_7:5.9.5:*:*:*:*:wordpress:*:*

Informations

Vendor

rocklobster

Product

contact_form_7

Version

5.9.5

Target Software

wordpress

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2025-3247 2025-04-16 05h23 +00:00 The Contact Form 7 plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 6.0.5 via the 'wpcf7_stripe_skip_spam_check' function due to insufficient validation on a user controlled key. This makes it possible for unauthenticated attackers to reuse a single Stripe PaymentIntent for multiple transactions. Only the first transaction is processed via Stripe, but the plugin sends a successful email message for each transaction, which may trick an administrator into fulfilling each order.
5.3
Moyen