Tech

Security flaw in top WordPress plugin could allow for Stripe refunds on millions of sites

Share
Share


  • Security researchers found a flaw in WPForms, a popular WordPress plugin for forms
  • The bug allows malicious actors to ask for Stripe refunds and cancel certain subscriptions
  • Developers were notified, and have issued a patch

WPForms, a popular WordPress plugin used for contact, feedback, and payment forms, was carrying a vulnerability that could have resulted in businesses having their services disrupted, customer trust eroded, and even losing money, experts have revealed.

Security researcher “vullu164” recently told Wordfence they found a vulnerability in WPForms versions 1.8.4 – 1.9.2, both free and paid versions. The bug allows users with low-level accounts to issue arbitrary Stripe refunds, or cancel different subscriptions.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
We just got another big hint that the Samsung Galaxy S25 FE is on the way
Tech

We just got another big hint that the Samsung Galaxy S25 FE is on the way

References to Galaxy S25 FE firmware have appeared The phone could launch...

You won’t believe what 700+ projectors and AI can do in Abu Dhabi’s new immersive art world
Tech

You won’t believe what 700+ projectors and AI can do in Abu Dhabi’s new immersive art world

Over 700 Epson projectors transform walls into moving, responsive works of living...

When the school bell rings, the bandwidth drops: How post-15:40 internet surges affect UK broadband quality
Tech

When the school bell rings, the bandwidth drops: How post-15:40 internet surges affect UK broadband quality

Half of parents work after school, causing a broadband battle with streaming-addicted...