What the vulnerability does
01Description
The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license delivery, and membership activation — without being charged.
Explanation of Vulnerability in Simple Terms
02Summary
Formidable Forms versions before 6.32.1 contain an integrity vulnerability allowing attackers to modify data without authentication. The attack requires specific network conditions and no user interaction. The vulnerability does not expose sensitive information or disrupt availability, but allows unauthorized alteration of form submissions or related data.
What an attacker can do
03Attacker Capabilities
Modify form data or submissions without logging in.
Potential impact on your site
04Site Impact
Form submissions or stored data could be altered by unauthorized parties.
Conditions required to exploit
05Prerequisites
Network access; specific conditions must be met (high attack complexity).
Key dates
06Disclosure timeline
August 6, 2026
CVE published