The Contact Form 7 plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 6.0.5 via the 'wpcf7_stripe_skip_spam_check' function due to insufficient validation on a user controlled key. This makes it possible for unauthenticated attackers to reuse a single Stripe PaymentIntent for multiple transactions. Only the first transaction is processed via Stripe, but the plugin sends a successful email message for each transaction, which may trick an administrator into fulfilling each order.
We have discovered 1,562,221 live websites that are affected by CVE-2025-3247.
| Product | |
| Category | Form Builders |
| Vulnerable Domains | 1,562,221 live websites (44% of Contact Form 7 install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 101 versions ( 81% of all versions) |
| 287,552 websites | |
| 176,051 websites | |
| 145,803 websites | |
| 97,912 websites | |
| 85,652 websites | |
| 64,536 websites | |
| 62,073 websites | |
| 52,511 websites | |
| 49,820 websites | |
| 48,927 websites |
| .com | 604,195 websites |
| .de | 82,693 websites |
| .it | 60,387 websites |
| .ru | 52,234 websites |
| .org | 47,999 websites |
| .nl | 42,793 websites |
| .net | 40,862 websites |
| .fr | 40,041 websites |
| .jp | 38,467 websites |
| .co.uk | 37,934 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.br | *** | ||
| ********.com | *,*** | ||
| ***.domains | *,*** | ||
| ************.com | *,*** | ||
| *******.org | *,*** | ||
| ************.com | *,*** | ||
| ***************.com | *,*** | ||
| *********.com | *,*** | ||
| ***************.com | *,*** | ||
| ***************.com | *,*** |
FAQ