CVE-2026-74991: WPForms Lite 1.8.8.2 - 2.0.1.1 - Unauthenticated Stripe Refund and Subscription Cancellation via External PaymentIntent
The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form submission belongs to it before acting on it, allowing unauthenticated users to trigger a full refund and an immediate subscription cancellation against payments created by other applications on the site owner's Stripe account.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Sites using the WPForms WordPress plugin before version 2.0.2 are affected. Exposure concerns Stripe payments on the site owner's Stripe account that were created by other applications.
Does an attacker need an account or prior access to exploit it?
No. The issue can be triggered by an unauthenticated user through a public form submission.
What can an attacker do with a supplied Stripe payment object?
They can cause a full refund and immediately cancel a subscription associated with payments created by other applications on the same Stripe account.
What should be updated?
Update WPForms to version 2.0.2 or later, as affected versions are before 2.0.2.