First published: Thu May 02 2024(Updated: )
The Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to price manipulation in versions up to, and including, 1.8.7.2. This is due to a lack of controls on several product parameters. This makes it possible for unauthenticated attackers to manipulate prices, product information, and quantities for purchases made via the Stripe payment integration.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPForms | <=1.8.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3649 is a high severity vulnerability that allows unauthenticated attackers to manipulate product pricing.
To fix CVE-2024-3649, update the WPForms plugin to version 1.8.7.3 or later.
CVE-2024-3649 affects all versions of the WPForms Contact Form plugin up to and including 1.8.7.2.
CVE-2024-3649 allows unauthorized users to manipulate product parameters, leading to price manipulation.
There are no known workarounds for CVE-2024-3649, so immediate updating is recommended.