What is CVE-2026-14236?
The Contact Form 7 plugin before version 2.5 lacks validation of the host in the user-supplied return URL used for Stripe checkout redirect targets. This allows an unauthenticated attacker to redirect a victim to an arbitrary external site after payment via a crafted link. Updating the plugin to the latest version is recommended.
Azərbaycanca: Contact Form 7 plugininin 2.5-dən əvvəlki versiyalarında Stripe ödənişi zamanı istifadə olunan qaytarılma URL-nin host hissəsinin yoxlanılmaması zəifliyi aşkarlanıb. Bu, autentifikasiya olunmamış hücumçuya xüsusi hazırlanmış keçid vasitəsilə qurbanı ödənişdən sonra ixtiyari xarici sayta yönləndirməyə imkan verir. Pluginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
What is the CVE-2026-14236 vulnerability in the Contact Form 7 plugin?
This vulnerability involves a lack of validation of the host portion of the user-supplied return URL used during Stripe checkout redirection in the Contact Form 7 plugin before version 2.5. This allows an unauthenticated attacker to redirect a victim to an arbitrary external site after payment via a crafted link.
How to protect against the CVE-2026-14236 vulnerability?
Updating the plugin to the latest version (2.5 or higher) is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.