Tech

Security flaw in top WordPress plugin could allow for Stripe refunds on millions of sites

Share
Share


  • Security researchers found a flaw in WPForms, a popular WordPress plugin for forms
  • The bug allows malicious actors to ask for Stripe refunds and cancel certain subscriptions
  • Developers were notified, and have issued a patch

WPForms, a popular WordPress plugin used for contact, feedback, and payment forms, was carrying a vulnerability that could have resulted in businesses having their services disrupted, customer trust eroded, and even losing money, experts have revealed.

Security researcher “vullu164” recently told Wordfence they found a vulnerability in WPForms versions 1.8.4 – 1.9.2, both free and paid versions. The bug allows users with low-level accounts to issue arbitrary Stripe refunds, or cancel different subscriptions.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Chatbots are on the rise, but customers still trust human agents more
Tech

Chatbots are on the rise, but customers still trust human agents more

Credit: CC0 Public Domain Customers contact companies regularly to purchase products and...

XO, Kitty season 3: everything we know so far about the hit show’s return to Netflix
Tech

XO, Kitty season 3: everything we know so far about the hit show’s return to Netflix

XO, Kitty season 3: key information – Officially renewed in February– Filming...

This monster 30TB hard drive costs less than 0 and is built for nonstop data hoarding
Tech

This monster 30TB hard drive costs less than $620 and is built for nonstop data hoarding

Seagate’s 30TB Exos M is helium-filled and built for data centers, not...

New technique hides encryption keys under user data using standard 3D NAND flash memory
Tech

New technique hides encryption keys under user data using standard 3D NAND flash memory

Flash memory now doubles as secure key storage using conceal-and-reveal method Encryption...