← Back
CVE-2026-6627
high
CVSS 8.2
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
Summary
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
AI summary openai / gpt-4o
WordPress用プラグインWPFormify – Stripe Payments with Form and Checkoutにおいて、未認証の攻撃者によるStripeの支払い資格情報の無許可の修正および削除が可能な脆弱性が発見されました。これにより、攻撃者はサイトのStripe API資格情報を改ざんし、自分のStripeアカウントに送金先を変更することができます。
❓ What is the problem
WordPress用のプラグインでStripeの支払い資格情報が無許可に修正・削除される脆弱性。
📍 Affected scope
WPFormifyプラグインのバージョン1.1.1以下。
🔥 Severity
未認証の攻撃者が支払情報を改ざんし、自らのアカウントにリダイレクト可能。
🔧 How to fix
最新版へのアップデートで脆弱性を修正。
🛡️ Workaround
情報なし
🔍 Detection
wpformifyプラグインのバージョンを確認することで影響有無を判断可能。