CERT-In Warns Of WPForms Vulnerability CVE-2024-11205
ID: 74fe1a63-e2ae-5c7d-b6a0-b881a48089ed
STIX ID: report--74fe1a63-e2ae-5c7d-b6a0-b881a48089ed
Feed Name: Cyble Blog
Threat Score
**Executive summary:** CVE-2024-11205 is a high-severity vulnerability in the WPForms WordPress plugin (v1.8.4–1.9.2.1) that allows authenticated users with Subscriber-level access to bypass authorization and invoke Stripe payment refund and subscription cancellation functionality; WPForms released a patch (v1.9.2.2) and Wordfence deployed firewall rules to mitigate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
