CVE-2024-3649

The Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to price manipulation in versions up to, and including, 1.8.7.2. This is due to a lack of controls on several product parameters. This makes it possible for unauthenticated attackers to manipulate prices, product information, and quantities for purchases made via the Stripe payment integration.
Configurations

No configuration.

History

No history.

Information

Published : 2024-05-02 17:15

Updated : 2026-06-17 07:44


NVD link : CVE-2024-3649

Mitre link : CVE-2024-3649

CVE.ORG link : CVE-2024-3649


JSON object : View

Products Affected

No product.

CWE
CWE-472

External Control of Assumed-Immutable Web Parameter