CVE-2026-85641: Formidable Forms 6.34 - Unauthenticated Stored Content Injection via 'updated_by' Parameter

Published Sep 16, 2026
·
Updated

The Formidable Forms WordPress plugin before 6.35 does not restrict who can set the identifier recording which user last edited a form entry, and relies on that identifier when deciding whether to strip HTML from stored entry values, allowing unauthenticated visitors to have markup rendered in the admin entry view that would otherwise be removed, and to attribute their submission to an administrator who never made it.

Affected Software

0 affected components

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Formidable Forms (WordPress plugin) to a version that resolves this vulnerability.

    Fixed in 6.35
  2. Configuration

    After upgrading, verify that Formidable Forms no longer allows unauthenticated visitors to set the 'updated_by' identifier for stored entry edits so that markup stripping/attribution logic is applied to the correct user.

    Formidable Forms (WordPress plugin) updated_by identifier restriction = Restrict who can set the 'updated_by' identifier to prevent unauthenticated users from attributing submissions

Event History

Sep 16, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Which installations are affected?

Formidable Forms versions before 6.35 are affected. The issue concerns form submissions whose stored values are later viewed in the WordPress admin entry view.

2

Does exploitation require an account or elevated permissions?

No. An unauthenticated visitor can submit data that causes markup to be retained and rendered in the admin entry view.

3

What conditions make exploitation more likely?

An attacker needs a form submission path and must be able to influence the updated_by parameter. The vulnerable logic uses that identifier when deciding whether HTML should be stripped from stored entry values.

4

What is the practical impact for administrators?

Markup supplied by an unauthenticated visitor may render when an administrator views the affected entry. The submission can also be attributed to an administrator who did not edit it.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203