"value":"The Forminator Forms \u2013 Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 1.42.0 via the 'handle_stripe_single' function due to insufficient validation on a user controlled key. This makes it possible for unauthenticated attackers to reuse a single Stripe PaymentIntent for multiple transactions. Only the first transaction is processed via Stripe, but the plugin sends a successful email message for each transaction, which may trick an administrator into fulfilling each order."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-354 Improper Validation of Integrity Check Value",
"cweId":"CWE-354"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"wpmudev",
"product":{
"product_data":[
{
"product_name":"Forminator Forms \u2013 Contact Form, Payment Form & Custom Form Builder",