CVE-2026-14236

Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect

The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow.


We have discovered 2,422 live websites that are affected by CVE-2026-14236.

Run a Free Instant Scan




Affected Software

Product  Contact Form 7 Paypal Add On
Category Wordpress Plugins
Vulnerable Domains2,422 live websites (95% of Contact Form 7 Paypal Add On install base)
Vulnerable Versions
  • from 0 through 2.5
Vulnerable Versions Count25 versions ( 96% of all versions)


Common Weakness Enumeration

CWE-601 URL Redirection to Untrusted Site ('Open Redirect')



Details

  • Published - Jul 27, 2026
  • Updated - Jul 27, 2026

Credits

  • Pedro Antunes (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-14236
United States1,109 websites



Italy195 websites
Germany169 websites
GB166 websites
France157 websites
Canada100 websites
Spain78 websites
Australia65 websites
Japan62 websites
Ireland34 websites

Website Distribution by TLD

Number of websites using CVE-2026-14236
.com1,064 websites
.org488 websites
.it149 websites
.co.uk93 websites
.de80 websites
.fr72 websites
.net52 websites
.com.au48 websites
.ca38 websites
.es26 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-14236

Top websites that are affected by CVE-2026-14236. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.org United States**,***
*****.it Italy***,***
******.com United States***,***
*****************.biz Germany***,***
***********.**.uk GB***,***
****************.org United States***,***
*************.com United States***,***
*************.com United States***,***
********.org United States***,***
*************.org Spain***,***
See full domain list

FAQ

CVE-2026-14236 is URL Redirection to Untrusted Site ('Open Redirect') in Contact Form 7 Paypal Add On
A total of 2,422 websites have been identified as vulnerable to CVE-2026-14236, based on global website indexing conducted by WebTechSurvey.
The Contact Form 7 Paypal Add On is affected by the CVE-2026-14236 vulnerability.
Contact Form 7 Paypal Add On versions up to 2.5 are vulnerable to CVE-2026-14236.
CVE-2026-14236 is resolved in version 2.5 of Contact Form 7 Paypal Add On.