Coinbase Business for Contact Form 7

Coinbase Business for Contact Form 7 has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; all 2 are fixed as of August 2026. Their average CVSS score is 5.2, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Missing Authorization.

Every one of the 2 issues recorded for Coinbase Business for Contact Form 7 has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Coinbase Business for Contact Form 7 is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
5.2/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Coinbase Business for Contact Form 7 vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2023-33999

Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get

Read the full analysis

Vulnerability Records

2 records
Plugin Profile
Latestv1.2.0

Coinbase Business for Contact Form 7

CoderPress

Author

CoderPress

5.0(2)
100/100
Last Updated
2026-05-18 (3mo ago)
Active Installs
10+
Downloads
4,132
Requires WP
4.9+
Requires PHP
7.4+
Tested up to
WP 6.9.7
Created
2022-03-24 (5y ago)

Documentation Coinbase Business for Contact Form 7 lets visitors submit a Contact Form 7 form and pay via a Coinbase Business hosted checkout. Payments are created with the Coinbase Business Checkouts API. Requirements WordPress with Contact Form 7 active A Coinbase Business account CDP Secret API keys from the Coinbase Developer Platform (ECDSA, with checkout permissions) A webhook subscription for checkout.payment.success pointing to the plugin webhook URL Setup Go to Contact → Coinbase Business Settings and save your CDP API key name and private key PEM. Copy the Webhook URL into your Coinbase Business webhook configuration and subscribe to checkout.payment.success. Paste the webhook secret from Coinbase into the plugin settings. Edit a Contact Form 7 form, open the Coinbase Business tab, enable payments, set price and currency (default USDC). How to Setup? Our other plugins Coinbase Commerce for WooCommerce Posts and Products Views for WooCommerce Emails Blacklist for Everest Forms

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C