Formidable Forms 6.34 - Unauthenticated Stored Content Injection via 'updated_by' Parameter
Summary
| CVE | CVE-2026-85641 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-16 06:16:34 UTC |
| Updated | 2026-09-16 06:16:34 UTC |
| Description | The Formidable Forms WordPress plugin before 6.35 does not restrict who can set the identifier recording which user last edited a form entry, and relies on that identifier when deciding whether to strip HTML from stored entry values, allowing unauthenticated visitors to have markup rendered in the admin entry view that would otherwise be removed, and to attribute their submission to an administrator who never made it. |
Risk And Classification
Problem Types: CWE-345 Insufficient Verification of Data Authenticity
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | Formidable Forms | affected 6.34 6.35 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/99933e4e-e371-4ba4-ad41-6849fcc6a5eb | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Karthik Ramakrishnan (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.