Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»SEO & Digital Marketing»Formidable Forms Flaw Lets Attackers Pay Less For Expensive Purchases
    SEO & Digital Marketing

    Formidable Forms Flaw Lets Attackers Pay Less For Expensive Purchases

    adminBy adminMarch 13, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Formidable Forms Flaw Lets Attackers Pay Less For Expensive Purchases
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A vulnerability in the Formidable Forms WordPress plugin installed on over 300,000 websites enables unauthenticated attackers to bypass payment verification. The vulnerability affects all versions up to and including 6.28. It makes it possible for attackers to reuse a Stripe payment made for a lower amount to mark a more expensive transaction as paid.

    Formidable Forms Plugin

    The Formidable Forms plugin is a drag-and-drop form builder used by WordPress sites to create contact forms, surveys, registration forms, and payment forms. Sites use it with payment processors (like PayPal and Stripe) to collect payments for services, memberships, digital products, and event registrations.

    Vulnerable To Unauthenticated Attackers

    What makes this vulnerability especially concerning is that it does not require authentication. An attacker does not need to log in or obtain even subscriber-level access to exploit the flaw. This makes it easier for attackers to take advantage of the payment validation weakness.

    The vulnerability has been assigned CVE-2026-2890 and carries a CVSS severity score of 7.5/10, which is rated High.

    Payment Integrity Bypass

    The vulnerability is due to missing validation in the handle_one_time_stripe_link_return_url function. The function marks payment records as complete based solely on the Stripe PaymentIntent status. This makes it possible for attackers to reuse a valid PaymentIntent for a smaller charge to approve a more expensive purchase.

    The verify_intent() function validates only that the client secret belongs to the user. It does not bind the PaymentIntent to a specific form submission. It does not verify that the amount charged matches the amount the customer was supposed to pay.

    According to Wordfence:

    “The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and including, 6.28. This is due to the Stripe Link return handler (`handle_one_time_stripe_link_return_url`) marking payment records as complete based solely on the Stripe PaymentIntent status without comparing the intent’s charged amount against the expected payment amount, and the `verify_intent()` function validating only client secret ownership without binding intents to specific forms or actions.

    This makes it possible for unauthenticated attackers to reuse a PaymentIntent from a completed low-value payment to mark a high-value payment as complete, effectively bypassing payment for goods or services.”

    This makes it possible for unauthenticated attackers to complete a small low-cost transaction and then reuse that PaymentIntent to approve a more expensive transaction without paying the full price.

    This vulnerability does not enable remote code execution or direct server compromise. But it does enable attackers to obtain goods or services without paying the required price.

    Affected Versions And Patch

    All versions up to and including 6.28 are affected. Users of the Formidable Forms plugin are encouraged by Wordfence to update to version 6.29 or newer to address the vulnerability.

    attackers expensive Flaw Formidable Forms lets Pay Purchases
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleHoly crap! The Galaxy S26 Ultra just ordered dinner and tea for me and all I had to do was hit ‘Confirm’
    Next Article Commercial Spyware Opponents Fear US Policy Shifting
    admin
    • Website

    Related Posts

    Google Says They Deploy Hundreds Of Undocumented Crawlers

    March 14, 2026

    Only 15% of pages retrieved by ChatGPT appear in final answers: Report

    March 14, 2026

    Why surface-level SEO tactics won’t build lasting AI search visibility

    March 14, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Google Says They Deploy Hundreds Of Undocumented Crawlers

    March 14, 2026

    Proof over promises: a new doctrine for cybersecurity

    March 14, 2026

    Microsoft investigates classic Outlook sync and connection issues

    March 14, 2026

    Microsoft is quietly turning Windows apps into websites, and New Outlook is a warning

    March 14, 2026
    Categories
    • Blogging (40)
    • Cybersecurity (772)
    • Privacy & Online Earning (120)
    • SEO & Digital Marketing (486)
    • Tech Tools & Mobile / Apps (945)
    • WiFi / Internet & Networking (129)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Google Says They Deploy Hundreds Of Undocumented Crawlers

    March 14, 2026

    Proof over promises: a new doctrine for cybersecurity

    March 14, 2026

    Microsoft investigates classic Outlook sync and connection issues

    March 14, 2026
    Most Popular
    • Google Says They Deploy Hundreds Of Undocumented Crawlers
    • Proof over promises: a new doctrine for cybersecurity
    • Microsoft investigates classic Outlook sync and connection issues
    • Microsoft is quietly turning Windows apps into websites, and New Outlook is a warning
    • Critical HPE AOS-CX Vulnerability Allows Admin Password Resets
    • Only 15% of pages retrieved by ChatGPT appear in final answers: Report
    • Google Messages is better than ever, but it still leaves me frustrated
    • New Qualcomm GBL exploit brings bootloader unlocking to flagship Androids
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.