CVE-2026-66660EPSS p24.3%
CVE-2026-66660CVE-2026-66660
Description
Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions.
Scoring
| CVSS | 6.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
| EPSS | 0.33% probability of exploitation · percentile 24.3% · 2026-10-06T12:00:23Z |
| Last modified | 2026-08-14 |