Medium severity5.9NVD Advisory· Published Aug 6, 2026
CVE-2026-11361
CVE-2026-11361
Description
The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license delivery, and membership activation — without being charged.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <6.32.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.