Unauthorized Payment Manipulation in WPForms Plugin by WPForms
CVE-2026-74991
Currently unrated
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-74991?
The WPForms plugin for WordPress, prior to version 2.0.2, is vulnerable due to a lack of validation on Stripe payment objects during public form submissions. As a result, unauthenticated users can exploit this weakness to initiate full refunds and cancel subscriptions associated with payments made on the site owner's Stripe account, allowing unauthorized manipulation of financial transactions.
Affected Version(s)
WPForms 1.8.8.2 < 2.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.