More

    Security flaw in top WordPress plugin could allow for Stripe refunds on millions of sites




    • Security researchers found a flaw in WPForms, a popular WordPress plugin for forms
    • The bug allows malicious actors to ask for Stripe refunds and cancel certain subscriptions
    • Developers were notified, and have issued a patch

    WPForms, a popular WordPress plugin used for contact, feedback, and payment forms, was carrying a vulnerability that could have resulted in businesses having their services disrupted, customer trust eroded, and even losing money, experts have revealed.

    Security researcher “vullu164” recently told Wordfence they found a vulnerability in WPForms versions 1.8.4 – 1.9.2, both free and paid versions. The bug allows users with low-level accounts to issue arbitrary Stripe refunds, or cancel different subscriptions.

    https://cdn.mos.cms.futurecdn.net/ebZTsHB4jGup8yK4ebtwyR-1200-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    spot_imgspot_img