CVE-2026-4986: WPForms Lite < 1.10.0.5 – Unauthenticated PayPal Webhook Forgery
The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WPFormsto a version that resolves this vulnerability.Fixed in 1.10.0.5 - Upgrade
Upgrade
WPForms Liteto a version that resolves this vulnerability.Fixed in 1.10.0.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4986?
CVE-2026-4986 has a risk rating of 62, indicating a significant security concern.
How do I fix CVE-2026-4986?
To fix CVE-2026-4986, update the WPForms plugin to version 1.10.0.5 or later.
What is the impact of CVE-2026-4986?
CVE-2026-4986 allows unauthenticated attackers to forge PayPal webhook payloads, potentially manipulating payment states.
Who is affected by CVE-2026-4986?
CVE-2026-4986 affects users of WPForms Lite versions prior to 1.10.0.5.
What kind of attacks can CVE-2026-4986 enable?
CVE-2026-4986 enables attackers to perform unauthorized actions related to payment transactions via forged webhook events.