CVE-2026-4986
WPForms Lite < 1.10.0.5 โ Unauthenticated PayPal Webhook Forgery
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.
| Vendor | unknown |
| Product | wpforms |
| Published | Jun 9, 2026 |
| Last Updated | Jun 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wpforms
Be the first to know when new medium vulnerabilities affecting unknown wpforms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WPForms
1.10.0.1 < 1.10.0.5
References
Credits
Sudhanshu Chauhan [RedHunt Labs] WPScan