๐Ÿ” CVE Alert

CVE-2026-4986

MEDIUM 5.3

WPForms Lite < 1.10.0.5 โ€“ Unauthenticated PayPal Webhook Forgery

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.

Vendor unknown
Product wpforms
Published Jun 9, 2026
Last Updated Jun 9, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wpforms

Be the first to know when new medium vulnerabilities affecting unknown wpforms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / WPForms
1.10.0.1 < 1.10.0.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/1d99eed6-9a16-4d5a-90f9-ab604dfd5b92/

Credits

Sudhanshu Chauhan [RedHunt Labs] WPScan