CVE-2026-4986
Deferred Deferred - Pending Action

Unauthenticated PayPal Webhook Forgery in WPForms WordPress Plugin

Vulnerability report for CVE-2026-4986, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-06-09

Last updated on: 2026-06-09

Assigner: WPScan

Description

The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-06-09
Last Modified
2026-06-09
Generated
2026-06-29
AI Q&A
2026-06-09
EPSS Evaluated
2026-06-28
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpforms wpforms_lite to 1.10.0.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Compliance Impact

The vulnerability allows unauthenticated attackers to forge PayPal webhook payloads and manipulate payment states of arbitrary transactions. This could lead to unauthorized financial transaction manipulations and potential data integrity issues.

Such unauthorized manipulation and lack of verification may impact compliance with standards and regulations like GDPR and HIPAA, which require ensuring data integrity, security, and protection against unauthorized access or modification of sensitive information.

However, the provided information does not explicitly describe the direct effects on compliance with these regulations.

Executive Summary

The vulnerability CVE-2026-4986 affects the WPForms Lite WordPress plugin versions prior to 1.10.0.5. It occurs because the plugin does not verify the authenticity of incoming PayPal webhook events before processing them.

This flaw allows unauthenticated attackers to forge webhook payloads, meaning they can send fake PayPal event data to the plugin.

As a result, attackers can manipulate the payment state of arbitrary transactions without needing to be authenticated.

Impact Analysis

This vulnerability can impact you by allowing attackers to alter the payment status of transactions processed by the WPForms plugin.

Such manipulation could lead to unauthorized changes in payment records, potentially causing financial discrepancies, fraud, or loss of revenue.

Because the attacker does not need to be authenticated, the risk of exploitation is higher.

Mitigation Strategies

To mitigate this vulnerability, you should update the WPForms Lite plugin to version 1.10.0.5 or later, as versions prior to this do not verify the authenticity of incoming PayPal webhook events.

Applying this update will prevent unauthenticated attackers from forging webhook payloads and manipulating the payment state of arbitrary transactions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-4986. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart