Impact
The WPForms WordPress plugin before version 2.0.2 contains a flaw that fails to confirm that a Stripe payment token supplied in a public form submission belongs to the site owner before processing withdrawals. This oversight allows any unauthenticated visitor to trigger a full refund and instantly cancel a subscription for payments created by other applications on the same Stripe account. The flaw is an improper authorization weakness, enabling attackers to compromise the financial integrity of the site without authentication.
Affected Systems
Affecting the WPForms plugin developed by WPForms, this vulnerability applies to all installations running the plugin in versions 1.8.8.2 through 2.0.1.1, inclusive. Site owners who have not upgraded to version 2.0.2 or later are potentially exposed. No specific operating system or web server requirements are indicated; the issue exists regardless of hosting environment as long as the vulnerable plugin is active.
Risk and Exploitability
The vulnerability poses a high severity risk because it enables unauthenticated users to initiate financial transactions that reverse or revoke payments, potentially causing significant revenue loss and trust damage. The EPSS score is unavailable, and the issue is not currently listed in the CISA KEV catalog, but the lack of authentication and the ease of exploitation via a standard web form indicate that attackers can leverage this flaw with minimal effort. The likely attack vector is a direct HTTP request to the plugin's public endpoint, and the absence of payment object validation means an adversary can simply paste any existing PaymentIntent ID from the site owner's Stripe account to exercise the action.
OpenCVE Enrichment