Improper Access Control in Formidable Forms Plugin for WordPress
CVE-2026-85641
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 16 September 2026
Badges
What is CVE-2026-85641?
The Formidable Forms plugin for WordPress prior to version 6.35 fails to properly restrict user permissions when setting the identifier for form entries. This lack of access control permits unauthenticated users to manipulate the identifier, which is used to determine HTML stripping in stored entry values. Consequently, malicious users can cause markup to be rendered in the administrative view, allowing them to attribute their submissions to an administrator. This exploitation can lead to serious security implications for WordPress sites using the plugin.
Affected Version(s)
Formidable Forms 6.34 < 6.35
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.