Reporter 11: 10 people found the WPForms PayPal bug before me (CVE-2026-4986)
TLDR WPForms Lite is a WordPress form plugin with 5 million plus active installations. Public advisory data identifies versions 1.10.0.1 through 1.10.0.4 as affected by CVE-2026-4986: the PayPal Commerce webhook processed incoming events without first verifying that PayPal actually sent them.
In my local lab, a forged event could change the state of a matching payment record. A forged PAYMENT.CAPTURE.COMPLETED event could mark a matching pending transaction as completed and trigger downstream payment-completed actions.