Security flaw in top WordPress plugin could allow for Stripe refunds on millions of sites




  • Security researchers found a flaw in WPForms, a popular WordPress plugin for forms
  • The bug allows malicious actors to ask for Stripe refunds and cancel certain subscriptions
  • Developers were notified, and have issued a patch

WPForms, a popular WordPress plugin used for contact, feedback, and payment forms, was carrying a vulnerability that could have resulted in businesses having their services disrupted, customer trust eroded, and even losing money, experts have revealed.

Security researcher “vullu164” recently told Wordfence they found a vulnerability in WPForms versions 1.8.4 – 1.9.2, both free and paid versions. The bug allows users with low-level accounts to issue arbitrary Stripe refunds, or cancel different subscriptions.

https://cdn.mos.cms.futurecdn.net/ebZTsHB4jGup8yK4ebtwyR-1200-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img