CVE Database /
CVE-2024-3649
CVE · Medium
CVE-2024-3649 — WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.8.8.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-3649
|
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.8.8.2 |
External Control of Assumed-Immutable Web Parameter |
Medium
5.3
|
< 1.8.8.2
|
1.8.8.2 |
2024-05-01 |
—
|
CVE-2024-3649
The WPForms plugin for WordPress contains a price manipulation vulnerability affecting versions up to 1.8.7.2. Unauthenticated attackers can modify product prices, details, and order quantities in transactions processed through the Stripe payment gateway because the plugin fails to properly validate several product-related parameters. This flaw allows unauthorized price changes for purchases made via the plugin's payment integration. The vulnerability was resolved in version 1.8.8.2.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings