{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/wpformify--stripe-payments-with-form-and-checkout--1.1.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-6627"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WPFormify – Stripe Payments with Form and Checkout (\u003c= 1.1.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe WPFormify - Stripe Payments with Form and Checkout plugin for WordPress, in versions up to and including 1.1.1, contains a critical authentication bypass vulnerability (CVE-2026-6627). The flaw resides in the wpf_stripe_callback_success() and wpf_stripe_disconnect() functions. These functions, which handle critical Stripe integration settings, are incorrectly hooked to the admin_init action. Because admin_init fires during requests to admin-post.php, and these functions lack necessary capability checks or nonce verification, unauthenticated remote attackers can interact with these endpoints. By sending crafted requests to admin-post.php, an attacker can overwrite existing Stripe API keys with their own, effectively redirecting all customer payments to a malicious account. Alternatively, an attacker may trigger the disconnect function to disrupt the site's payment processing capabilities entirely. This vulnerability poses a high financial risk to any organization using the plugin for payment collection.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to hijack payment flows, leading to complete loss of transaction revenue or service disruption. All WordPress sites running WPFormify version 1.1.1 or lower are affected. There is no information provided regarding the total number of victims, but the nature of the vulnerability facilitates direct financial fraud.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the WPFormify - Stripe Payments with Form and Checkout plugin to the latest version immediately to remediate the missing capability checks.\u003c/li\u003e\n\u003cli\u003eReview WordPress audit logs for unexpected POST requests to admin-post.php, specifically those originating from unauthenticated sessions that invoke Stripe-related parameters.\u003c/li\u003e\n\u003cli\u003eAudit current Stripe configuration settings in the WordPress admin panel to verify that the configured API keys match authorized merchant account values.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T09:16:35Z","date_published":"2026-08-05T09:16:35Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wpformify-stripe-auth-bypass/","summary":"An unauthenticated vulnerability in the WPFormify plugin allows attackers to overwrite or delete Stripe API credentials via missing capability checks on admin-post.php.","title":"Unauthenticated Stripe Credential Modification in WPFormify WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-wpformify-stripe-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - WPFormify – Stripe Payments With Form and Checkout (\u003c= 1.1.1)","version":"https://jsonfeed.org/version/1.1"}