PT-2026-47131 · WordPress · Wpforms

·

CVE-2026-7792

·

Published

2026-06-06

·

Updated

2026-06-07

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More versions prior to 1.10.0.2
Description The plugin is subject to insufficient verification of data authenticity. The PayPal Commerce webhook endpoint processes unauthenticated JSON webhook payloads without verifying the HMAC-SHA256 webhook signature, which is required to ensure the request originated from PayPal. The system only checks if the event type is whitelisted before sending attacker-controlled resource data to handlers that update payment records. This allows unauthenticated attackers with a valid subscription id to forge PayPal webhook events and modify subscription payment records, such as changing the subscription status to active to reactivate a cancelled or suspended subscription.
Recommendations Update to a version later than 1.10.0.1.

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7792

Affected Products

Wpforms