CVE-2024-11205

WPForms 1.8.4 - 1.9.2.1 - Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription Cancellation

The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' function in versions starting from 1.8.4 up to, and including, 1.9.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to refund payments and cancel subscriptions.


We have discovered 115,344 live websites that are affected by CVE-2024-11205.

Run a Free Instant Scan




Affected Software

Product  WPForms
Category Form Builders
Vulnerable Domains115,344 live websites (20.93% of WPForms install base)
Vulnerable Versions
  • from 1.8.4 through 1.9.2.1
Vulnerable Versions Count40 versions ( 20.00% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Dec 10, 2024
  • Updated - Dec 10, 2024

Credits

  • Villu Orav (finder)

CVE-2024-11205 usage by Country

United States39,793 websites



Germany15,342 websites
France7,683 websites
Cyprus5,770 websites
GB4,906 websites
Italy3,690 websites
Netherlands2,743 websites
Spain2,511 websites
Poland2,311 websites
South Africa1,912 websites

CVE-2024-11205 usage by TLD

.com50,836 websites
.de5,782 websites
.org5,383 websites
.co.uk3,664 websites
.fr3,237 websites
.nl2,998 websites
.it2,911 websites
.net2,505 websites
.com.br2,467 websites
.com.au2,107 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-11205

Top websites that are affected by CVE-2024-11205. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com Germany*,***
*******.com Netherlands*,***
******.com United States*,***
***********************.com United States*,***
*******.com United States*,***
*******.org Germany*,***
*************.com United States*,***
****.bg Bulgaria*,***
****************.org United States**,***
*********.com United States**,***
See full domain list

FAQ

CVE-2024-11205 is Missing Authorization in WPForms
A total of 115,344 websites have been identified as vulnerable to CVE-2024-11205, based on global website indexing conducted by WebTechSurvey.
The WPForms is affected by the CVE-2024-11205 vulnerability.
WPForms versions up to and including 1.9.2.1 are vulnerable to CVE-2024-11205.