The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.
References
Configurations
No configuration.
History
09 Jun 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
| CWE | CWE-862 |
09 Jun 2026, 06:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-09 06:16
Updated : 2026-06-17 10:57
NVD link : CVE-2026-4986
Mitre link : CVE-2026-4986
CVE.ORG link : CVE-2026-4986
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
