The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow.
We have discovered 2,422 live websites that are affected by CVE-2026-14236.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 2,422 live websites (95% of Contact Form 7 Paypal Add On install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 25 versions ( 96% of all versions) |
| 1,109 websites | |
| 195 websites | |
| 169 websites | |
| 166 websites | |
| 157 websites | |
| 100 websites | |
| 78 websites | |
| 65 websites | |
| 62 websites | |
| 34 websites |
| .com | 1,064 websites |
| .org | 488 websites |
| .it | 149 websites |
| .co.uk | 93 websites |
| .de | 80 websites |
| .fr | 72 websites |
| .net | 52 websites |
| .com.au | 48 websites |
| .ca | 38 websites |
| .es | 26 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **************.org | **,*** | ||
| *****.it | ***,*** | ||
| ******.com | ***,*** | ||
| *****************.biz | ***,*** | ||
| ***********.**.uk | ***,*** | ||
| ****************.org | ***,*** | ||
| *************.com | ***,*** | ||
| *************.com | ***,*** | ||
| ********.org | ***,*** | ||
| *************.org | ***,*** |
FAQ