Description
The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license delivery, and membership activation — without being charged.
Published: 2026-08-06
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Formidable Forms WordPress plugin until version 6.32.1 fails to validate the PayPal subscription status before marking a payment as complete, permitting an unauthenticated user to trigger any paid form action—such as granting access to digital content, delivering license keys, or activating memberships—without completing payment. This flaw relates to insufficient validation of external inputs (CWE‑345) and creates a clear path for revenue loss and unauthorized content distribution.

Affected Systems

Vendors: Formidable Forms. Product: the Formidable Forms WordPress plugin. Affected versions: any installation running a version prior to 6.32.1.

Risk and Exploitability

The CVSS score of 5.9 categorizes the issue as moderate, and the EPSS score of < 1% indicates a very low exploitation probability. No listing in the CISA KEV catalog suggests limited exploitation reports. The vulnerability allows an unauthenticated user to activate paid form actions by manipulating the PayPal subscription status. While the CVE description does not specify the exact attack method, a potential approach inferred from the behavior might involve forging a webhook or altering request data to the plugin’s PayPal integration endpoint. While the exact attack path is not fully documented, the described behavior provides a clear opportunity for revenue loss and unauthorized content distribution.

Generated by OpenCVE AI on August 7, 2026 at 17:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Formidable Forms plugin to version 6.32.1 or later.
  • If an upgrade cannot be performed immediately, disable any PayPal-triggered paid form actions until the plugin is patched to prevent unauthorized access.
  • Verify that all existing subscription payments have been processed and re‑confirm access permissions for any users who may have received paid content before the patch was applied.

Generated by OpenCVE AI on August 7, 2026 at 17:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Formidableforms
Formidableforms formidable
Wordpress
Wordpress wordpress
Vendors & Products Formidableforms
Formidableforms formidable
Wordpress
Wordpress wordpress

Fri, 07 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-287

Fri, 07 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-345
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-287

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license delivery, and membership activation — without being charged.
Title Formidable Forms < 6.32.1 - Unauthenticated Payment Bypass via PayPal APPROVAL_PENDING Subscription Status
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Formidableforms Formidable
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-07T13:45:09.753Z

Reserved: 2026-06-05T11:38:05.399Z

Link: CVE-2026-11361

cve-icon Vulnrichment

Updated: 2026-08-07T13:45:03.287Z

cve-icon NVD

Status : Deferred

Published: 2026-08-06T22:16:44.690

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-11361

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T20:53:48Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity