PT-2026-47131 · WordPress · Wpforms
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More versions prior to 1.10.0.2
Description
The plugin is subject to insufficient verification of data authenticity. The PayPal Commerce webhook endpoint processes unauthenticated JSON webhook payloads without verifying the HMAC-SHA256 webhook signature, which is required to ensure the request originated from PayPal. The system only checks if the
event type is whitelisted before sending attacker-controlled resource data to handlers that update payment records. This allows unauthenticated attackers with a valid subscription id to forge PayPal webhook events and modify subscription payment records, such as changing the subscription status to active to reactivate a cancelled or suspended subscription.Recommendations
Update to a version later than 1.10.0.1.
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpforms