Close Menu
SkytikSkytik

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    At Least 32 People Dead After a Mine Bridge Collapsed Due to Overcrowding

    November 17, 2025

    Here’s how I turned a Raspberry Pi into an in-car media server

    November 17, 2025

    Beloved SF cat’s death fuels Waymo criticism

    November 17, 2025
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    SkytikSkytik
    • Home
    • AI Tools
    • Online Tools
    • Tech News
    • Guides
    • Reviews
    • SEO & Marketing
    • Social Media Tools
    SkytikSkytik
    Home»SEO & Marketing»Formidable Forms Flaw Lets Attackers Pay Less For Expensive Purchases
    SEO & Marketing

    Formidable Forms Flaw Lets Attackers Pay Less For Expensive Purchases

    AwaisBy AwaisMarch 13, 2026No Comments3 Mins Read0 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Formidable Forms Flaw Lets Attackers Pay Less For Expensive Purchases
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A vulnerability in the Formidable Forms WordPress plugin installed on over 300,000 websites enables unauthenticated attackers to bypass payment verification. The vulnerability affects all versions up to and including 6.28. It makes it possible for attackers to reuse a Stripe payment made for a lower amount to mark a more expensive transaction as paid.

    Formidable Forms Plugin

    The Formidable Forms plugin is a drag-and-drop form builder used by WordPress sites to create contact forms, surveys, registration forms, and payment forms. Sites use it with payment processors (like PayPal and Stripe) to collect payments for services, memberships, digital products, and event registrations.

    Vulnerable To Unauthenticated Attackers

    What makes this vulnerability especially concerning is that it does not require authentication. An attacker does not need to log in or obtain even subscriber-level access to exploit the flaw. This makes it easier for attackers to take advantage of the payment validation weakness.

    The vulnerability has been assigned CVE-2026-2890 and carries a CVSS severity score of 7.5/10, which is rated High.

    Payment Integrity Bypass

    The vulnerability is due to missing validation in the handle_one_time_stripe_link_return_url function. The function marks payment records as complete based solely on the Stripe PaymentIntent status. This makes it possible for attackers to reuse a valid PaymentIntent for a smaller charge to approve a more expensive purchase.

    The verify_intent() function validates only that the client secret belongs to the user. It does not bind the PaymentIntent to a specific form submission. It does not verify that the amount charged matches the amount the customer was supposed to pay.

    According to Wordfence:

    “The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and including, 6.28. This is due to the Stripe Link return handler (`handle_one_time_stripe_link_return_url`) marking payment records as complete based solely on the Stripe PaymentIntent status without comparing the intent’s charged amount against the expected payment amount, and the `verify_intent()` function validating only client secret ownership without binding intents to specific forms or actions.

    This makes it possible for unauthenticated attackers to reuse a PaymentIntent from a completed low-value payment to mark a high-value payment as complete, effectively bypassing payment for goods or services.”

    This makes it possible for unauthenticated attackers to complete a small low-cost transaction and then reuse that PaymentIntent to approve a more expensive transaction without paying the full price.

    This vulnerability does not enable remote code execution or direct server compromise. But it does enable attackers to obtain goods or services without paying the required price.

    Affected Versions And Patch

    All versions up to and including 6.28 are affected. Users of the Formidable Forms plugin are encouraged by Wordfence to update to version 6.29 or newer to address the vulnerability.

    Attackers expensive flaw Formidable forms lets Pay Purchases
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Awais
    • Website

    Related Posts

    LinkedIn updates feed algorithm with LLM-powered ranking and retrieval

    March 17, 2026

    Trust Is The New Ranking Factor

    March 17, 2026

    What incrementality really means in affiliate marketing

    March 17, 2026

    3 CMS Platforms Control 73% Of The Market & Shape Technical SEO Defaults

    March 17, 2026

    Google tests “Sponsored Shops” blocks in Shopping results

    March 16, 2026

    AI Search Barely Cites Syndicated News Or Press Releases

    March 16, 2026
    Leave A Reply Cancel Reply

    Top Posts

    At Least 32 People Dead After a Mine Bridge Collapsed Due to Overcrowding

    November 17, 20250 Views

    Here’s how I turned a Raspberry Pi into an in-car media server

    November 17, 20250 Views

    Beloved SF cat’s death fuels Waymo criticism

    November 17, 20250 Views
    Don't Miss

    Generalizing Real-World Robot Manipulation via Generative Visual Transfer

    March 17, 2026

    [Submitted on 26 Sep 2025 (v1), last revised 16 Mar 2026 (this version, v2)] Authors:Zhehao…

    LinkedIn updates feed algorithm with LLM-powered ranking and retrieval

    March 17, 2026

    Trust Is The New Ranking Factor

    March 17, 2026

    CLAG: Adaptive Memory Organization via Agent-Driven Clustering for Small Language Model Agents

    March 17, 2026
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    What incrementality really means in affiliate marketing

    March 17, 2026

    3 CMS Platforms Control 73% Of The Market & Shape Technical SEO Defaults

    March 17, 2026
    Most Popular

    13 Trending Songs on TikTok in Nov 2025 (+ How to Use Them)

    November 18, 20257 Views

    How to watch the 2026 GRAMMY Awards online from anywhere

    February 1, 20263 Views

    Corporate Reputation Management Strategies | Sprout Social

    November 19, 20252 Views
    Our Picks

    At Least 32 People Dead After a Mine Bridge Collapsed Due to Overcrowding

    November 17, 2025

    Here’s how I turned a Raspberry Pi into an in-car media server

    November 17, 2025

    Beloved SF cat’s death fuels Waymo criticism

    November 17, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions
    • Disclaimer

    © 2025 skytik.cc. All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.