AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-11361

MEDIUM · CVSS 5.9 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Formidable Forms WordPress plugin prior to version 6.32.1 is vulnerable due to inadequate validation of PayPal subscription payment statuses, enabling unauthenticated users to exploit this flaw and gain unauthorized access to paid features, including digital content and memberships. This could lead to financial losses for businesses relying on the plugin for monetization. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-11361
Severity
MEDIUM
CVSS
5.9
EPSS
0.14%
WordPress

Original NVD Description

The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license delivery, and membership activation — without being charged.