PT-2026-97705 · WordPress · Wpforms
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
WPForms versions prior to 2.0.2
Description
An issue exists where the plugin fails to verify if a Stripe payment object provided during a public form submission actually belongs to the plugin before processing it. This allows unauthenticated users to trigger full refunds and immediate subscription cancellations for payments generated by other applications linked to the site owner's Stripe account.
Recommendations
Update to version 2.0.2 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpforms