---
id: CVE-2026-105990
title: >-
  The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7
  does not perform any authorization checks before exporting stored form
  submissions, allowing unauthenticated attackers to download the personal data
  (name, ema…
summary: >-
  The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7
  does not perform any authorization checks before exporting stored form
  submissions, allowing unauthenticated attackers to download the personal data
  (name, ema…
severity: none
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T06:16:40.677'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105990'
references:
  - url: 'https://wpscan.com/vulnerability/211d7613-a7e0-45f9-b262-66651aa4f535/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-10-10T06:24:42.863Z'
---

## Overview

The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization checks before exporting stored form submissions, allowing unauthenticated attackers to download the personal data (name, email, telephone, postal address, message) and payment metadata of everyone who submitted a payment form.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
