MEDIUM
Formidable Forms
CVE published 2026-08-06
CVE-2026-11361
The Formidable Forms WordPress plugin, prior to version 6.32.1, contains a vulnerability that allows unauthenticated users to bypass payment and trigger paid form actions, such as digital content access, license delivery, and membership activation, without being charged. This issue arises from the plugin's inadequate payment validation mechanism, which fails to verify the legitimacy of PayPal subscription [truncated]