Back to CVE List

CVE-2026-4986

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
5.3 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Vulnerability Description

The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-862
Source
NVD

External References

Discussion (0)

Add Comment

No comments yet. Be the first!