WPForms
cpe:2.3:a:wpforms:wpforms:*:*:*:*:wordpress:*:*
- < 1.10.0.5
A vulnerability exists in the WPForms WordPress plugin in versions prior to 1.10.0.5, where the plugin fails to authenticate incoming PayPal webhook events before processing them. This flaw allows unauthenticated attackers to create fake webhook payloads and alter the payment status of any transaction.
Exploitation of this vulnerability could lead to unauthorized manipulation of payment states for transactions processed through PayPal.
Users are advised to update the WPForms WordPress plugin to version 1.10.0.5 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.