CVE-2026-11361: Formidable Forms < 6.32.1 - Unauthenticated Payment Bypass via PayPal APPROVAL_PENDING Subscription Status
The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license delivery, and membership activation — without being charged.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11361?
The severity of CVE-2026-11361 is classified as medium with a score of 5.9.
How do I fix CVE-2026-11361?
To fix CVE-2026-11361, update the Formidable Forms WordPress plugin to version 6.32.1 or later.
What type of vulnerability is CVE-2026-11361?
CVE-2026-11361 is an unauthenticated payment bypass vulnerability that allows users to trigger paid form actions.
Who is affected by CVE-2026-11361?
Users of the Formidable Forms WordPress plugin versions prior to 6.32.1 are affected by CVE-2026-11361.
What actions can unauthenticated users perform due to CVE-2026-11361?
Unauthenticated users can bypass payments and access restricted actions such as digital content and membership delivery due to CVE-2026-11361.