CVE-2026-85641
Received Received - Intake

Unauthenticated HTML Rendering in Formidable Forms WordPress Plugin

Vulnerability report for CVE-2026-85641, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: WPScan

Description

The Formidable Forms WordPress plugin before 6.35 does not restrict who can set the identifier recording which user last edited a form entry, and relies on that identifier when deciding whether to strip HTML from stored entry values, allowing unauthenticated visitors to have markup rendered in the admin entry view that would otherwise be removed, and to attribute their submission to an administrator who never made it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
formidable_forms formidable_forms to 6.35 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Formidable Forms WordPress plugin before version 6.35. It allows unauthenticated users to inject HTML markup into form entries by manipulating the 'updated_by' parameter. The plugin fails to restrict who can set the identifier for the last user who edited an entry, which is used to decide whether to strip HTML from stored values. This can lead to stored content injection.

Detection Guidance

Check your Formidable Forms plugin version. If it is below 6.35, the vulnerability is present. You can verify this via WordPress admin panel under Plugins or by running the command: wp plugin list --name=formidable --fields=name,version in a WordPress environment with WP-CLI installed.

Impact Analysis

Unauthenticated visitors could inject malicious markup that renders in the admin entry view, potentially leading to phishing attacks or misleading administrators. Attackers can also falsely attribute submissions to administrators who never made them, causing confusion or reputational damage.

Compliance Impact

This vulnerability could lead to unauthorized data modification or injection of malicious content, potentially violating integrity requirements in GDPR and HIPAA. It may also expose sensitive admin views to untrusted markup, risking confidentiality.

Mitigation Strategies

Update the Formidable Forms plugin to version 6.35 or later immediately. This version contains the fix for the vulnerability. You can update via the WordPress admin panel or using the command: wp plugin update formidable in a WordPress environment with WP-CLI installed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85641. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart