logo

CVE-2024-11205: WPForms Plugin Vulnerability Exposes 6 Million WordPress Sites to Financial Risk

ID: e2ead42b-b7ea-5812-821d-9296de448d24

STIX ID: report--e2ead42b-b7ea-5812-821d-9296de448d24

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2024-12-10

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

A critical vulnerability (CVE-2024-11205, CVSS 8.5) was found in WPForms (versions 1.8.4–1.9.2.1) that permits authenticated users with subscriber-level privileges to trigger Stripe refunds and cancel subscriptions by abusing AJAX handlers (ajax_single_payment_refund and ajax_single_payment_cancel) due to missing authorization checks in wpforms_is_admin_ajax; a patched version (1.9.2.2) and mitigations are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.