CVE-2026-4986 PUBLISHED

WPForms Lite < 1.10.0.5 – Unauthenticated PayPal Webhook Forgery

Assigner: WPScan
Reserved: 27.03.2026 Published: 09.06.2026 Updated: 09.06.2026

The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.

Product Status

Vendor Unknown
Product WPForms
Versions Default: unaffected
  • affected from 1.10.0.1 to 1.10.0.5 (excl.)

Credits

  • Sudhanshu Chauhan [RedHunt Labs] finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE