The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-06-09 06:16
Updated : 2026-07-23 08:10
NVD link : CVE-2026-4986
Mitre link : CVE-2026-4986
CVE.ORG link : CVE-2026-4986
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
