logo

WPForms bug allows Stripe refunds on millions of WordPress sites

ID: 9f98d77a-ce03-589b-847d-f3a5e279f975

STIX ID: report--9f98d77a-ce03-589b-847d-f3a5e279f975

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-12-10

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

A high-severity authorization vulnerability (CVE-2024-11205) in the WPForms WordPress plugin allowed authenticated subscriber users to call admin AJAX functions to issue Stripe refunds and cancel subscriptions; the flaw affects versions 1.8.4–1.9.2.1, was patched in 1.9.2.2, and site owners are advised to update or disable the plugin because millions of sites may be vulnerable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.