cleantalk
Vulnerabilities and Security Researches

Contact Form by WPForms – Drag & Drop Form Builder for WordPress, CVE-2026-4986

CVE, Research URL

CVE-2026-4986

Published on
Jun 09, 2026
Research Description
The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.
Affected versions
max 1.10.0.5.
Status
vulnerable