Skip to main content

Threat intelligence

Contact Form 7 – PayPal & Stripe Add-on <= 2.4.9 - Unauthenticated Payment Bypass via Insufficient Verification of Data Authenticity via PayPal IPN Handler ('invoice'/'mc_gross' Verification)

CVE-2026-9189 · contact-form-7-paypal-add-on

Important: Seeing this vulnerability listed does not mean your website is affected. Exposure depends on whether you run Contact Form 7 Paypal Add On at a vulnerable version. How SiteRespond intelligence works

Vulnerability
Contact Form 7 – PayPal & Stripe Add-on <= 2.4.9 - Unauthenticated Payment Bypass via Insufficient Verification of Data Authenticity via PayPal IPN Handler ('invoice'/'mc_gross' Verification)
Affected software
contact-form-7-paypal-add-on(Plugin)
Affected versions
  • ≤ 2.4.9
Authentication
Unauthenticated
Vulnerability type
Other
Published
28 May 2026
CISA KEV
Not listed in CISA KEV at last catalog refresh
Impact
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Source

Data imported from Wordfence Intelligence (advisory 5e274781-1c20-4224-bc10-26dadb9b1e07). Methodology and redistribution notes

Check whether your installed version is affected

SiteRespond Defence matches your installed Contact Form 7 Paypal Add On version against this catalog when the Defence plugin is connected to your WordPress site.