HomeDefault status
unaffected
1.10.0.1 (semver) before 1.10.0.5
affected
Description
The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.
Problem types
Product status
1.10.0.1 (semver) before 1.10.0.5
Credits
Sudhanshu Chauhan [RedHunt Labs]
WPScan
References
wpscan.com/...rability/1d99eed6-9a16-4d5a-90f9-ab604dfd5b92/