Price Manipulation Vulnerability in WPForms - Drag & Drop Form Builder
CVE-2024-3649
5.3MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 2 May 2024
What is CVE-2024-3649?
The WPForms - Drag & Drop Form Builder plugin for WordPress suffers from a price manipulation vulnerability due to insufficient validation on key product parameters. This allows unauthenticated attackers to alter pricing, product information, and quantities during checkout processes involving Stripe payments. Users are strongly advised to update to the latest version to mitigate potential exploitation risks.
Affected Version(s)
Contact Form by WPForms – Drag & Drop Form Builder for WordPress * <= 1.8.7.2