CVE-2026-4986
Received Received - Intake
Unauthenticated PayPal Webhook Forgery in WPForms WordPress Plugin

Publication date: 2026-06-09

Last updated on: 2026-06-09

Assigner: WPScan

Description
The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-09
Last Modified
2026-06-09
Generated
2026-06-09
AI Q&A
2026-06-09
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
wpforms wpforms_lite to 1.10.0.5 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The vulnerability CVE-2026-4986 affects the WPForms Lite WordPress plugin versions prior to 1.10.0.5. It occurs because the plugin does not verify the authenticity of incoming PayPal webhook events before processing them.

This flaw allows unauthenticated attackers to forge webhook payloads, meaning they can send fake PayPal event data to the plugin.

As a result, attackers can manipulate the payment state of arbitrary transactions without needing to be authenticated.

Impact Analysis

This vulnerability can impact you by allowing attackers to alter the payment status of transactions processed by the WPForms plugin.

Such manipulation could lead to unauthorized changes in payment records, potentially causing financial discrepancies, fraud, or loss of revenue.

Because the attacker does not need to be authenticated, the risk of exploitation is higher.

Mitigation Strategies

To mitigate this vulnerability, you should update the WPForms Lite plugin to version 1.10.0.5 or later, as versions prior to this do not verify the authenticity of incoming PayPal webhook events.

Applying this update will prevent unauthenticated attackers from forging webhook payloads and manipulating the payment state of arbitrary transactions.

Compliance Impact

The vulnerability allows unauthenticated attackers to forge PayPal webhook payloads and manipulate payment states of arbitrary transactions. This could lead to unauthorized financial transaction manipulations and potential data integrity issues.

Such unauthorized manipulation and lack of verification may impact compliance with standards and regulations like GDPR and HIPAA, which require ensuring data integrity, security, and protection against unauthorized access or modification of sensitive information.

However, the provided information does not explicitly describe the direct effects on compliance with these regulations.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-4986. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart