CVE-2025-3247
Status: AnalyzedMedium (5.3)—
The Contact Form 7 plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 6.0.5 via the 'wpcf7_stripe_skip_spam_check' function due to insufficient validation on a user controlled key. This makes it possible for unauthenticated attackers to reuse a single Stripe PaymentIntent for multiple transactions. Only the first transaction is processed via Stripe, but the plugin sends a successful email message for each transaction, which may trick an administrator into fulfilling each order.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Base score: 5.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.25%
- Percentile among all scored CVEs: 15
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-354
References
Raw JSON (NVD)
Show
{
"id": "CVE-2025-3247",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-3247",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-04-16T13:23:21.654939Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@wordfence.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@wordfence.com",
"affectedData": [
{
"vendor": "rocklobsterinc",
"product": "Contact Form 7",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "6.0.5"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-04-16T06:15:42.933",
"references": [
{
"url": "https://plugins.trac.wordpress.org/browser/contact-form-7/tags/6.0.5/modules/stripe/stripe.php#L114",
"tags": [
"Broken Link",
"Product"
],
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3270138/",
"tags": [
"Broken Link",
"Patch"
],
"source": "security@wordfence.com"
},
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/38257dbf-288e-4028-af65-85f5389888ac?source=cve",
"tags": [
"Third Party Advisory"
],
"source": "security@wordfence.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@wordfence.com",
"description": [
{
"lang": "en",
"value": "CWE-354"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Contact Form 7 plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 6.0.5 via the 'wpcf7_stripe_skip_spam_check' function due to insufficient validation on a user controlled key. This makes it possible for unauthenticated attackers to reuse a single Stripe PaymentIntent for multiple transactions. Only the first transaction is processed via Stripe, but the plugin sends a successful email message for each transaction, which may trick an administrator into fulfilling each order."
},
{
"lang": "es",
"value": "El complemento Contact Form 7 para WordPress es vulnerable a la repetición de pedidos en todas las versiones hasta la 6.0.5 incluida, a través de la función 'wpcf7_stripe_skip_spam_check', debido a una validación insuficiente en una clave controlada por el usuario. Esto permite que atacantes no autenticados reutilicen un único PaymentIntent de Stripe para múltiples transacciones. Solo la primera transacción se procesa a través de Stripe, pero el plugin envía un correo electrónico con cada transacción realizada correctamente, lo que puede engañar al administrador para que complete cada pedido."
}
],
"lastModified": "2026-06-17T09:19:30.750",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:rocklobster:contact_form_7:*:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "E6C3AAB5-EA58-4D4F-BC1D-3B92CE46E134",
"versionEndExcluding": "6.0.6"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@wordfence.com"
}