Tech

Security flaw in top WordPress plugin could allow for Stripe refunds on millions of sites

Share
Share


  • Security researchers found a flaw in WPForms, a popular WordPress plugin for forms
  • The bug allows malicious actors to ask for Stripe refunds and cancel certain subscriptions
  • Developers were notified, and have issued a patch

WPForms, a popular WordPress plugin used for contact, feedback, and payment forms, was carrying a vulnerability that could have resulted in businesses having their services disrupted, customer trust eroded, and even losing money, experts have revealed.

Security researcher “vullu164” recently told Wordfence they found a vulnerability in WPForms versions 1.8.4 – 1.9.2, both free and paid versions. The bug allows users with low-level accounts to issue arbitrary Stripe refunds, or cancel different subscriptions.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Samsung’s next pair of affordable Galaxy earbuds could come with a battery boost
Tech

Samsung’s next pair of affordable Galaxy earbuds could come with a battery boost

The Samsung Galaxy Buds Core have leaked again It looks as though...

Microsoft Teams adds ‘Prevent Screen Capture’ meeting mode to secure sensitive data
Tech

Microsoft Teams adds ‘Prevent Screen Capture’ meeting mode to secure sensitive data

Enhanced Meeting Protection will block you from taking unwarranted screenshots It’ll turn...

How AI helps push Candy Crush players through its most difficult puzzles
Tech

How AI helps push Candy Crush players through its most difficult puzzles

This image provided by King.com Limited shows the “Candy Crush Saga” video...

iOS 19 tipped to bring big Wi-Fi convenience upgrade, as iOS 18.5 prepares to land in days
Tech

iOS 19 tipped to bring big Wi-Fi convenience upgrade, as iOS 18.5 prepares to land in days

iOS 19 could make it easier to connect multiple devices to public...