Insufficient Verification of Data Authenticity in WPForms by WPForms
CVE-2026-7792

5.3MEDIUM

What is CVE-2026-7792?

A vulnerability exists in the WPForms – Easy Form Builder for WordPress plugin where the PayPal Commerce webhook endpoint fails to authenticate JSON webhook payloads. This issue arises because the webhook does not verify the origin of requests from PayPal, relying solely on a whitelist of event types. As a result, unauthenticated attackers can exploit this flaw by sending forged PayPal webhook events, which may allow them to manipulate subscription payment records—potentially reactivating canceled or suspended subscriptions by altering the subscription status.

Affected Version(s)

WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More 0 <= 1.10.0.4

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vijay
.