CyberRota Analysis
AI-GeneratedThe Formidable Forms WordPress plugin prior to version 6.32.1 is vulnerable due to inadequate validation of PayPal subscription payment statuses, enabling unauthenticated users to exploit this flaw and gain unauthorized access to paid features, including digital content and memberships. This could lead to financial losses for businesses relying on the plugin for monetization. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license delivery, and membership activation — without being charged.