WPMU DEV Forminator
cpe:2.3:a:wpmudev:forminator_forms:*:*:*:*:wordpress:*:*
- <= 1.52.0
A vulnerability exists in the Forminator plugin for WordPress, specifically in versions up to and including 1.52.0. The issue stems from the plugin's failure to properly verify user authorization when handling Stripe PaymentIntent identifiers in the public payment flow. This oversight allows unauthenticated attackers to exploit the system by reusing low-value PaymentIntents to complete high-value paid forms, creating conditions for underpayment or payment bypass.
Exploitation of this vulnerability allows for unauthorized completion of paid forms, leading to underpayment or payment bypass.
Users are advised to update the Forminator plugin to version 1.52.1 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.