logo

CERT-In Warns Of WPForms Vulnerability CVE-2024-11205

ID: 74fe1a63-e2ae-5c7d-b6a0-b881a48089ed

STIX ID: report--74fe1a63-e2ae-5c7d-b6a0-b881a48089ed

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2025-03-03

Date Updated: 2026-07-20

...
...

**Executive summary:** CVE-2024-11205 is a high-severity vulnerability in the WPForms WordPress plugin (v1.8.4–1.9.2.1) that allows authenticated users with Subscriber-level access to bypass authorization and invoke Stripe payment refund and subscription cancellation functionality; WPForms released a patch (v1.9.2.2) and Wordfence deployed firewall rules to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.