CVE-2026-74991: Unknown Wpforms
Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.
The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form submission belongs to it before acting on it, allowing unauthenticated users to trigger a full refund and an immediate subscription cancellation against payments created by other applications on the site owner's Stripe account.
Affected products
- Unknown Wpforms: from 1.8.8.2, before 2.0.2 (fixed in 2.0.2)
Published 2026-09-24. Last modified 2026-09-24.