5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Description
The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.
Basic Information
ID
CVE-2026-4986
Source
WPScan
Published
Jun 9, 2026 at 06:00
Modified
Jun 9, 2026 at 13:15
Affected Product
Vendor
Unknown
Product
WPForms
Version
1.10.0.1
Affected Versions
Unknown WPForms 1.10.0.1