ZealousWeb WordPress Plugin Accept Authorize.NET Payments Vulnerability in Contact Form 7

Vulnerability

A vulnerability allowing the insertion of sensitive information into sent data has been identified in the ZealousWeb WordPress plugin 'Accept Authorize.NET Payments Using Contact Form 7', affecting versions through 2.5. This vulnerability could allow unauthorized retrieval of embedded sensitive data, which is typically not accessible to regular users.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information, potentially allowing for further exploitation of other weaknesses in the system.

Remediation

Users of the 'Accept Authorize.NET Payments Using Contact Form 7' WordPress plugin should update to version 2.6 or later to address this vulnerability. Patchstack users can enable auto-update for vulnerable plugins.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.