CVE-2026-11361 MEDIUM

CVE-2026-11361: Formidable Forms < 6.32.1 - Unauthenticated Payment Bypass via PayPal APPROVAL_PENDING Subscription Status

Vendor Unknown
Product Formidable Forms
Published August 6, 2026
Last update August 6, 2026

CVSS base score

5.9/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license delivery, and membership activation — without being charged.

Explanation of Vulnerability in Simple Terms

02Summary

Formidable Forms versions before 6.32.1 contain an integrity vulnerability allowing attackers to modify data without authentication. The attack requires specific network conditions and no user interaction. The vulnerability does not expose sensitive information or disrupt availability, but allows unauthorized alteration of form submissions or related data.

What an attacker can do

03Attacker Capabilities

Modify form data or submissions without logging in.

Potential impact on your site

04Site Impact

Form submissions or stored data could be altered by unauthorized parties.

Conditions required to exploit

05Prerequisites

Network access; specific conditions must be met (high attack complexity).

Key dates

06Disclosure timeline

August 6, 2026 CVE published