Executive brief
WPForms, a popular WordPress plugin used for creating contact and payment forms, contains a security flaw in how it handles PayPal payments. An attacker can send fake payment notifications to a website, tricking the system into thinking a payment was completed or modified when it was not. This could allow users to bypass payment requirements or disrupt the financial records of a business.
Technical details
The WPForms plugin (specifically the Lite version) fails to perform cryptographic signature verification or origin validation on incoming PayPal webhook notifications. This vulnerability is classified as Missing Authorization (CWE-862). An unauthenticated remote attacker can send specially crafted HTTP POST requests to the webhook listener endpoint, mimicking legitimate PayPal notifications. This allows the attacker to manipulate the payment status of arbitrary transactions within the WordPress database, such as marking an unpaid order as 'Completed'. The issue is resolved in version 1.10.0.5.
Affected products
- WPForms WPForms Lite < 1.10.0.5
Timeline
- 2026-05-19: disclosed: Publicly published by WPScan
- 2026-05-19: patched: Fixed in version 1.10.0.5
- 2026-06-09: advisory: CVE published to NVD dataset