CVE-2024-12255

The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 via the cf7sa-info.php file that returns phpinfo() data. This makes it possible for unauthenticated attackers to extract configuration information that can be leveraged in another attack.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zealousweb:accept_stripe_payments_using_contact_form_7:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2024-12-12 06:15

Updated : 2025-07-02 20:06


NVD link : CVE-2024-12255

Mitre link : CVE-2024-12255

CVE.ORG link : CVE-2024-12255


JSON object : View

Products Affected

zealousweb

  • accept_stripe_payments_using_contact_form_7
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-732

Incorrect Permission Assignment for Critical Resource