CVE-2026-14236: Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect
The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14236?
The severity of CVE-2026-14236 is rated at 23, indicating a significant security risk.
How do I fix CVE-2026-14236?
To fix CVE-2026-14236, update the Contact Form 7 PayPal & Stripe Add-on plugin to version 2.5 or later.
Who is affected by CVE-2026-14236?
Users of the Contact Form 7 WordPress plugin PayPal & Stripe Add-on prior to version 2.5 are affected by CVE-2026-14236.
What type of vulnerability is CVE-2026-14236?
CVE-2026-14236 is an Open Redirect vulnerability that allows an attacker to manipulate redirect targets.
Can CVE-2026-14236 lead to phishing attacks?
Yes, CVE-2026-14236 can be exploited to redirect users to arbitrary external sites, potentially leading to phishing attacks.