What is CVE-2026-4986?
An authentication vulnerability was discovered in the WPForms PayPal Commerce addon. While the webhook route is public by design, the core issue is the lack of proper authentication after the request is received, potentially allowing unauthorized actions. Users are advised to update the addon to the latest version.
Azərbaycanca: WPForms PayPal Commerce əlavəsində autentifikasiya zəifliyi aşkarlanıb. Webhook ümumi olsa da, əsas problem sorğu qəbul edildikdən sonra baş verən autentifikasiya çatışmazlığıdır ki, bu da icazəsiz əməliyyatlara səbəb ola bilər. İstifadəçilərə əlavəni ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306; shared vendor: PayPal
FAQ2
What can the CVE-2026-4986 vulnerability in the WPForms PayPal Commerce addon allow?
The CVE-2026-4986 vulnerability can lead to unauthorized actions due to a lack of proper authentication after the request is received.
What should users do to protect against the CVE-2026-4986 vulnerability?
Users are advised to update the WPForms PayPal Commerce addon to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.