Impact
The WPForms Lite plugin for WordPress, before version 1.10.0.5, fails to verify the source of PayPal webhook notifications. An attacker can send forged webhook payloads that the plugin processes as authentic, allowing manipulation of the payment status of any transaction recorded by the site. This authority bypass can result in fraudulent payments, unauthorized refunds, or improper order status changes, directly affecting the financial integrity of the site.
Affected Systems
This vulnerability affects any WordPress installation that has WPForms Lite installed at a version earlier than 1.10.0.5. Site owners using the older Lite edition, irrespective of the WordPress core version, are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, but the EPSS below 1% and lack of listing in CISA KEV suggest low current exploitation likelihood. Nonetheless, an unauthenticated attacker can remotely satisfy the conditions by sending HTTP POST requests to the webhook endpoint, as the plugin accepts all payloads without authentication checks. The low exploitation probability does not negate the potential financial damage inherent in modifying payment records.
OpenCVE Enrichment