Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-11361

Опубликовано: 06 авг. 2026
Источник: nvd
CVSS3: 5.9
EPSS Низкий

Описание

The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license delivery, and membership activation — without being charged.

EPSS

Процентиль: 4%
0.00141
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 5.9
github
12 дней назад

The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license delivery, and membership activation — without being charged.

EPSS

Процентиль: 4%
0.00141
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-345