CVE-2026-74991
WPForms Lite 1.8.8.2 - 2.0.1.1 - Unauthenticated Stripe Refund and Subscription Cancellation via External PaymentIntent
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form submission belongs to it before acting on it, allowing unauthenticated users to trigger a full refund and an immediate subscription cancellation against payments created by other applications on the site owner's Stripe account.
| Vendor | unknown |
| Product | wpforms |
| Published | Sep 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wpforms
Be the first to know when new unknown vulnerabilities affecting unknown wpforms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WPForms
1.8.8.2 < 2.0.2
References
Credits
Charles Vosburgh WPScan