CVE-2026-11361: Unknown Formidable Forms
Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.
The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license delivery, and membership activation — without being charged.
Affected products
- Unknown Formidable Forms: before 6.32.1 (fixed in 6.32.1)
Published 2026-08-06. Last modified 2026-08-26.