Feed/CVE-2026-14236
CVE-2026-14236MEDIUMCVSS 4.7

CVE-2026-14236

Published Jul 27, 2026·Updated Jul 27, 2026

NVD Description

The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free