WordPress Plugin Vulnerabilities
Formidable Forms < 6.32.1 - Unauthenticated Payment Bypass via PayPal APPROVAL_PENDING Subscription Status
Description
The plugin does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license delivery, and membership activation — without being charged.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Yaswanth Reddy Sunkara
Submitter
Yaswanth Reddy Sunkara
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-06-25 (about 2 months ago)
Added
2026-06-25 (about 2 months ago)
Last Updated
2026-06-25 (about 2 months ago)