5.3
CVE-2025-3479
- EPSS 0.06%
- Veröffentlicht 17.04.2025 11:13:06
- Zuletzt bearbeitet 28.05.2025 17:54:30
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
Forminator <= 1.42.0 - Order Replay Vulnerability
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 1.42.0 via the 'handle_stripe_single' function due to insufficient validation on a user controlled key. This makes it possible for unauthenticated attackers to reuse a single Stripe PaymentIntent for multiple transactions. Only the first transaction is processed via Stripe, but the plugin sends a successful email message for each transaction, which may trick an administrator into fulfilling each order.
Mögliche Gegenmaßnahme
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: Update to version 1.42.1, or a newer patched version
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
Version
*-1.42.0
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wpmudev ≫ Forminator Forms SwEditionfree SwPlatformwordpress Version < 1.42.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.171 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
CWE-354 Improper Validation of Integrity Check Value
The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.