CVE-2026-39707
Missing Authorization vulnerability in ZealousWeb Accept PayPal Payments using Contact Form 7 contact-form-7-paypal-extension allows Exploit
CVSS
5.3
Medium
EPSS
0.2%
p9
KEV
—
Exploit Today
3
0-100
Published: Apr 8, 2026 · Last modified: Jul 24, 2026 · CWE-862
0.2%EPSS · 30 days0.2%
2026-07-132026-08-10
Missing Authorization vulnerability in ZealousWeb Accept PayPal Payments using Contact Form 7 contact-form-7-paypal-extension allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accept PayPal Payments using Contact Form 7: from n/a through <= 4.0.4.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-703408.1 HIG—
———Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.5hCVE-2026-658066.5 MED—
———Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.5hCVE-2026-629156.5 MED—
———Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.5hCVE-2026-619365.5 MED—
———Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.5hCVE-2026-591138.8 HIG—
———Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.5hCVE-2026-403756.5 MED—
———Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.5h