Improper Access Control in Formidable Forms Plugin for WordPress
CVE-2026-85641

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-85641?

The Formidable Forms plugin for WordPress prior to version 6.35 fails to properly restrict user permissions when setting the identifier for form entries. This lack of access control permits unauthenticated users to manipulate the identifier, which is used to determine HTML stripping in stored entry values. Consequently, malicious users can cause markup to be rendered in the administrative view, allowing them to attribute their submissions to an administrator. This exploitation can lead to serious security implications for WordPress sites using the plugin.

Affected Version(s)

Formidable Forms 6.34 < 6.35

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Karthik Ramakrishnan
WPScan
.