<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>WPFormify – Stripe Payments With Form and Checkout (&lt;= 1.1.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/wpformify--stripe-payments-with-form-and-checkout--1.1.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 05 Aug 2026 09:16:35 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/wpformify--stripe-payments-with-form-and-checkout--1.1.1/feed.xml" rel="self" type="application/rss+xml"/><item><title>Unauthenticated Stripe Credential Modification in WPFormify WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-08-wpformify-stripe-auth-bypass/</link><pubDate>Wed, 05 Aug 2026 09:16:35 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-wpformify-stripe-auth-bypass/</guid><description>An unauthenticated vulnerability in the WPFormify plugin allows attackers to overwrite or delete Stripe API credentials via missing capability checks on admin-post.php.</description><content:encoded><![CDATA[<p>The WPFormify - Stripe Payments with Form and Checkout plugin for WordPress, in versions up to and including 1.1.1, contains a critical authentication bypass vulnerability (CVE-2026-6627). The flaw resides in the wpf_stripe_callback_success() and wpf_stripe_disconnect() functions. These functions, which handle critical Stripe integration settings, are incorrectly hooked to the admin_init action. Because admin_init fires during requests to admin-post.php, and these functions lack necessary capability checks or nonce verification, unauthenticated remote attackers can interact with these endpoints. By sending crafted requests to admin-post.php, an attacker can overwrite existing Stripe API keys with their own, effectively redirecting all customer payments to a malicious account. Alternatively, an attacker may trigger the disconnect function to disrupt the site's payment processing capabilities entirely. This vulnerability poses a high financial risk to any organization using the plugin for payment collection.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to hijack payment flows, leading to complete loss of transaction revenue or service disruption. All WordPress sites running WPFormify version 1.1.1 or lower are affected. There is no information provided regarding the total number of victims, but the nature of the vulnerability facilitates direct financial fraud.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the WPFormify - Stripe Payments with Form and Checkout plugin to the latest version immediately to remediate the missing capability checks.</li>
<li>Review WordPress audit logs for unexpected POST requests to admin-post.php, specifically those originating from unauthenticated sessions that invoke Stripe-related parameters.</li>
<li>Audit current Stripe configuration settings in the WordPress admin panel to verify that the configured API keys match authorized merchant account values.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>