PT-2026-78352 · WordPress · Balbooa Forms
CVSS v4.0
7.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Balbooa Forms versions prior to 2.4.3.2
Description
An issue exists where the 'stripeCharges' and 'payAuthorize' endpoints accept the charge total from a client-controlled request parameter and forward it to the payment gateway without recomputing it based on the configured product prices. Additionally, these endpoints do not enforce authentication or Cross-Site Request Forgery (CSRF) checks. This allows an unauthenticated attacker to purchase priced items for an arbitrary amount and forge line items, quantities, and shipping details.
Recommendations
Update Balbooa Forms to version 2.4.3.2 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Balbooa Forms