
WPForms PayPal Webhook Vulnerability Disclosed (CVE-2026-4986)
cybersecurityvulnerabilitywebhookPayPalWPFormsCVE-2026-4986authentication
A reporter disclosed being the 11th individual to identify a vulnerability in the WPForms PayPal Commerce webhook (CVE-2026-4986). The flaw involved an authentication failure where the system processed PayPal events before verifying the sender’s identity, allowing forged events to alter payment records in affected versions. The issue was resolved in WPForms version 1.10.0.5, with the researcher noting that at least 11 people independently reported the same bug.