PT-2026-47688 · Undefined · Undefined

Published

2026-06-09

·

Updated

2026-06-09

·

CVE-2026-4986

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.

Exploit

Related Identifiers

CVE-2026-4986

Affected Products

Undefined