Description
The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form submission belongs to it before acting on it, allowing unauthenticated users to trigger a full refund and an immediate subscription cancellation against payments created by other applications on the site owner's Stripe account.
Published: 2026-09-24
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthenticated Refund and Subscription Cancellation
Action: Apply Upgrade
AI Analysis

Impact

The WPForms WordPress plugin before version 2.0.2 contains a flaw that fails to confirm that a Stripe payment token supplied in a public form submission belongs to the site owner before processing withdrawals. This oversight allows any unauthenticated visitor to trigger a full refund and instantly cancel a subscription for payments created by other applications on the same Stripe account. The flaw is an improper authorization weakness, enabling attackers to compromise the financial integrity of the site without authentication.

Affected Systems

Affecting the WPForms plugin developed by WPForms, this vulnerability applies to all installations running the plugin in versions 1.8.8.2 through 2.0.1.1, inclusive. Site owners who have not upgraded to version 2.0.2 or later are potentially exposed. No specific operating system or web server requirements are indicated; the issue exists regardless of hosting environment as long as the vulnerable plugin is active.

Risk and Exploitability

The vulnerability poses a high severity risk because it enables unauthenticated users to initiate financial transactions that reverse or revoke payments, potentially causing significant revenue loss and trust damage. The EPSS score is unavailable, and the issue is not currently listed in the CISA KEV catalog, but the lack of authentication and the ease of exploitation via a standard web form indicate that attackers can leverage this flaw with minimal effort. The likely attack vector is a direct HTTP request to the plugin's public endpoint, and the absence of payment object validation means an adversary can simply paste any existing PaymentIntent ID from the site owner's Stripe account to exercise the action.

Generated by OpenCVE AI on September 24, 2026 at 07:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update WPForms to version 2.0.2 or later to patch the authorization flaw.
  • Restrict the public form endpoint or add authentication so that only authorized users can submit payment tokens.
  • Review and monitor Stripe logs for unauthorized refunds or subscription cancellations, and revoke any affected Stripe API keys if necessary.

Generated by OpenCVE AI on September 24, 2026 at 07:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpforms
Wpforms wpforms
Weaknesses CWE-285
CWE-862
Vendors & Products Wordpress
Wordpress wordpress
Wpforms
Wpforms wpforms

Thu, 24 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form submission belongs to it before acting on it, allowing unauthenticated users to trigger a full refund and an immediate subscription cancellation against payments created by other applications on the site owner's Stripe account.
Title WPForms Lite 1.8.8.2 - 2.0.1.1 - Unauthenticated Stripe Refund and Subscription Cancellation via External PaymentIntent
References

Subscriptions

Wordpress Wordpress
Wpforms Wpforms
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-24T06:00:16.110Z

Reserved: 2026-08-17T12:02:45.425Z

Link: CVE-2026-74991

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-24T06:17:00.943

Modified: 2026-09-24T06:17:00.943

Link: CVE-2026-74991

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T07:30:16Z

Weaknesses