Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ww4h-86qv-rmr8

Опубликовано: 07 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license delivery, and membership activation — without being charged.

The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license delivery, and membership activation — without being charged.

EPSS

Процентиль: 4%
0.00141
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 5.9
nvd
12 дней назад

The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license delivery, and membership activation — without being charged.

EPSS

Процентиль: 4%
0.00141
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-345