Insufficient Verification of Data Authenticity in WPForms by WPForms
CVE-2026-7792
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 June 2026
What is CVE-2026-7792?
A vulnerability exists in the WPForms – Easy Form Builder for WordPress plugin where the PayPal Commerce webhook endpoint fails to authenticate JSON webhook payloads. This issue arises because the webhook does not verify the origin of requests from PayPal, relying solely on a whitelist of event types. As a result, unauthenticated attackers can exploit this flaw by sending forged PayPal webhook events, which may allow them to manipulate subscription payment records—potentially reactivating canceled or suspended subscriptions by altering the subscription status.
Affected Version(s)
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More 0 <= 1.10.0.4