WPForms Plugin Vulnerability Affects Up To 6 Million Sites
The WPForms plugin for WordPress exposes websites to a vulnerability that allows attackers to update subscriptions and issue refunds. This flaw enables attackers to modify data they normally should not have access to. Missing Capability Check The vulnerability is due to a missing capability check in a function within the plugin called wpforms_is_admin_page, which means … Read more