CVE-2026-4986
Received
Received - Intake
Unauthenticated PayPal Webhook Forgery in WPForms WordPress Plugin
Publication date: 2026-06-09
Last updated on: 2026-06-09
Assigner: WPScan
Description
Description
The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wpforms | wpforms_lite | to 1.10.0.5 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |