CVE-2024-3649

The Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to price manipulation in versions up to, and including, 1.8.7.2. This is due to a lack of controls on several product parameters. This makes it possible for unauthenticated attackers to manipulate prices, product information, and quantities for purchases made via the Stripe payment integration.
Configurations

No configuration.

History

08 Apr 2026, 18:21

Type Values Removed Values Added
CWE CWE-472

21 Nov 2024, 09:30

Type Values Removed Values Added
References () https://plugins.trac.wordpress.org/changeset/3075634 - () https://plugins.trac.wordpress.org/changeset/3075634 -
References () https://plugins.trac.wordpress.org/changeset/3075634/wpforms-lite/trunk/assets/js/integrations/stripe/wpforms-stripe-payment-element.js - () https://plugins.trac.wordpress.org/changeset/3075634/wpforms-lite/trunk/assets/js/integrations/stripe/wpforms-stripe-payment-element.js -
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/68a509ae-9943-4b9a-8ede-2b5732e96e6d?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/68a509ae-9943-4b9a-8ede-2b5732e96e6d?source=cve -
Summary
  • (es) El complemento Contact Form by WPForms – Drag & Drop Form Builder para WordPress es vulnerable a la manipulación de precios en versiones hasta la 1.8.7.2 incluida. Esto se debe a la falta de controles sobre varios parámetros del producto. Esto hace posible que atacantes no autenticados manipulen precios, información de productos y cantidades de compras realizadas a través de la integración de pagos de Stripe.

02 May 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-02 17:15

Updated : 2026-04-15 00:35


NVD link : CVE-2024-3649

Mitre link : CVE-2024-3649

CVE.ORG link : CVE-2024-3649


JSON object : View

Products Affected

No product.

CWE
CWE-472

External Control of Assumed-Immutable Web Parameter