CVE-2026-66660

WordPress Contact Form 7 – PayPal & Stripe Add-on plugin <= 2.5.1 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions.


We have discovered 2,507 live websites that are affected by CVE-2026-66660.

Run a Free Instant Scan




Affected Software

Product  Contact Form 7 Paypal Add On
Category Wordpress Plugins
Vulnerable Domains2,507 live websites (100% of Contact Form 7 Paypal Add On install base)
Vulnerable Versions
  • from 0 through 2.5.1
Vulnerable Versions Count26 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Aug 13, 2026
  • Updated - Aug 13, 2026

Credits

  • dodoh4t | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-66660
United States1,156 websites



Italy201 websites
GB186 websites
Germany172 websites
France161 websites
Canada103 websites
Spain80 websites
Japan65 websites
Australia63 websites
Ireland33 websites

Website Distribution by TLD

Number of websites using CVE-2026-66660
.com1,081 websites
.org527 websites
.it152 websites
.co.uk104 websites
.de85 websites
.fr71 websites
.net57 websites
.com.au47 websites
.ca41 websites
.es27 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-66660

Top websites that are affected by CVE-2026-66660. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.org United States**,***
*****.it Italy***,***
******.com United States***,***
****************.org United States***,***
*****************.biz Germany***,***
***************.com Spain***,***
***********.**.uk GB***,***
***********.org United States***,***
****************.org United States***,***
*************.com United States***,***
See full domain list

FAQ

CVE-2026-66660 is Missing Authorization in Contact Form 7 Paypal Add On
A total of 2,507 websites have been identified as vulnerable to CVE-2026-66660, based on global website indexing conducted by WebTechSurvey.
The Contact Form 7 Paypal Add On is affected by the CVE-2026-66660 vulnerability.
Contact Form 7 Paypal Add On versions up to and including 2.5.1 are vulnerable to CVE-2026-66660.