Impact
The Formidable Forms WordPress plugin until version 6.32.1 fails to validate the PayPal subscription status before marking a payment as complete, permitting an unauthenticated user to trigger any paid form action—such as granting access to digital content, delivering license keys, or activating memberships—without completing payment. This flaw relates to insufficient validation of external inputs (CWE‑345) and creates a clear path for revenue loss and unauthorized content distribution.
Affected Systems
Vendors: Formidable Forms. Product: the Formidable Forms WordPress plugin. Affected versions: any installation running a version prior to 6.32.1.
Risk and Exploitability
The CVSS score of 5.9 categorizes the issue as moderate, and the EPSS score of < 1% indicates a very low exploitation probability. No listing in the CISA KEV catalog suggests limited exploitation reports. The vulnerability allows an unauthenticated user to activate paid form actions by manipulating the PayPal subscription status. While the CVE description does not specify the exact attack method, a potential approach inferred from the behavior might involve forging a webhook or altering request data to the plugin’s PayPal integration endpoint. While the exact attack path is not fully documented, the described behavior provides a clear opportunity for revenue loss and unauthorized content distribution.
OpenCVE Enrichment