CVE-2024-11205: WPForms Plugin Vulnerability Exposes 6 Million WordPress Sites to Financial Risk
ID: e2ead42b-b7ea-5812-821d-9296de448d24
STIX ID: report--e2ead42b-b7ea-5812-821d-9296de448d24
Feed Name: The Cyber Express
Threat Score
A critical vulnerability (CVE-2024-11205, CVSS 8.5) was found in WPForms (versions 1.8.4–1.9.2.1) that permits authenticated users with subscriber-level privileges to trigger Stripe refunds and cancel subscriptions by abusing AJAX handlers (ajax_single_payment_refund and ajax_single_payment_cancel) due to missing authorization checks in wpforms_is_admin_ajax; a patched version (1.9.2.2) and mitigations are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
