What is CVE-2026-11361?
The Formidable Forms WordPress plugin before version 6.32.1 fails to properly validate PayPal subscription payment status, allowing unauthenticated attackers to bypass payment and trigger paid form actions like accessing digital content. Site administrators should immediately update the plugin to the latest version.
Azərbaycanca: WordPress-in Formidable Forms plugin-inin 6.32.1-dən əvvəlki versiyalarında PayPal ödəniş statusunun düzgün yoxlanılmaması səbəbindən autentifikasiya olunmamış istifadəçilər ödənişi keçərək rəqəmsal məzmun əldə edə bilər. Sayt sahibləri plugin-i dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-306; shared vendor: PayPal
FAQ2
Which versions of the Formidable Forms plugin are affected by CVE-2026-11361?
Versions of the Formidable Forms plugin before 6.32.1 are affected.
What can an attacker gain by exploiting CVE-2026-11361?
An unauthenticated attacker can bypass PayPal payment status validation and trigger paid form actions, such as accessing digital content, without paying.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.