๐Ÿ” CVE Alert

CVE-2026-74991

UNKNOWN 0.0

WPForms Lite 1.8.8.2 - 2.0.1.1 - Unauthenticated Stripe Refund and Subscription Cancellation via External PaymentIntent

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form submission belongs to it before acting on it, allowing unauthenticated users to trigger a full refund and an immediate subscription cancellation against payments created by other applications on the site owner's Stripe account.

Vendor unknown
Product wpforms
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wpforms

Be the first to know when new unknown vulnerabilities affecting unknown wpforms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / WPForms
1.8.8.2 < 2.0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/e539d37e-91bb-4d79-b812-ac3c6c1a0f70/

Credits

Charles Vosburgh WPScan