PT-2026-78352 · WordPress · Balbooa Forms

·

CVE-2026-67363

·

Published

2026-08-19

·

Updated

2026-08-20

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Balbooa Forms versions prior to 2.4.3.2
Description An issue exists where the 'stripeCharges' and 'payAuthorize' endpoints accept the charge total from a client-controlled request parameter and forward it to the payment gateway without recomputing it based on the configured product prices. Additionally, these endpoints do not enforce authentication or Cross-Site Request Forgery (CSRF) checks. This allows an unauthenticated attacker to purchase priced items for an arbitrary amount and forge line items, quantities, and shipping details.
Recommendations Update Balbooa Forms to version 2.4.3.2 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67363

Affected Products

Balbooa Forms