CVE-2024-12255: Accept Stripe Payments Using Contact Form 7 <= 2.5 - Unauthenticated Information Exposure
The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 via the cf7sa-info.php file that returns phpinfo() data. This makes it possible for unauthenticated attackers to extract configuration information that can be leveraged in another attack.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12255?
CVE-2024-12255 is classified as a medium severity vulnerability due to potential information exposure.
How do I fix CVE-2024-12255?
To fix CVE-2024-12255, you should update the Accept Stripe Payments Using Contact Form 7 plugin to version 2.6 or later.
Who is affected by CVE-2024-12255?
All users of the Accept Stripe Payments Using Contact Form 7 plugin for WordPress up to and including version 2.5 are affected by CVE-2024-12255.
What kind of information is exposed by CVE-2024-12255?
CVE-2024-12255 allows attackers to retrieve sensitive configuration information via the phpinfo() function.
Is authentication required to exploit CVE-2024-12255?
No, CVE-2024-12255 can be exploited by unauthenticated attackers.