CVE-2024-12250

MEDIUM

Accept Authorize.NET Payments Using Contact Form 7 <2.2 - Info Disc...

Title source: llm
STIX 2.1

Description

The Accept Authorize.NET Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2 via the cf7adn-info.php file. This makes it possible for unauthenticated attackers to extract configuration data which can be used to aid in other attacks.

Scores

CVSS v3 5.3
EPSS 0.0037
EPSS Percentile 28.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
zealopensource/Accept Authorize.NET Payments Using Contact Form 7 < 2.2
Published Dec 18, 2024
Tracked Since Feb 18, 2026