CVE · Medium

CVE-2024-3649 — WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.8.8.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3649 WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.8.8.2 External Control of Assumed-Immutable Web Parameter Medium 5.3 < 1.8.8.2 1.8.8.2 2024-05-01

CVE-2024-3649

The WPForms plugin for WordPress contains a price manipulation vulnerability affecting versions up to 1.8.7.2. Unauthenticated attackers can modify product prices, details, and order quantities in transactions processed through the Stripe payment gateway because the plugin fails to properly validate several product-related parameters. This flaw allows unauthorized price changes for purchases made via the plugin's payment integration. The vulnerability was resolved in version 1.8.8.2.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.