CVE-2025-3247: Contact Form 7 <= 6.0.5 - Order Replay Vulnerability
The Contact Form 7 plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 6.0.5 via the 'wpcf7stripeskipspamcheck' function due to insufficient validation on a user controlled key. This makes it possible for unauthenticated attackers to reuse a single Stripe PaymentIntent for multiple transactions. Only the first transaction is processed via Stripe, but the plugin sends a successful email message for each transaction, which may trick an administrator into fulfilling each order.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/contact-form-7to a version that resolves this vulnerability.Fixed in 6.0.5Patch Order Replay Vulnerability
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3247?
CVE-2025-3247 is considered a high severity vulnerability as it allows unauthenticated attackers to exploit the Order Replay issue.
How do I fix CVE-2025-3247?
To fix CVE-2025-3247, you should update the Contact Form 7 plugin to version 6.0.6 or higher.
What versions of Contact Form 7 are affected by CVE-2025-3247?
CVE-2025-3247 affects all versions of Contact Form 7 up to and including 6.0.5.
Is authentication needed to exploit CVE-2025-3247?
No, CVE-2025-3247 can be exploited by unauthenticated attackers.
What functionality does CVE-2025-3247 compromise?
CVE-2025-3247 compromises the Order Replay functionality in the Contact Form 7 plugin.