
Formidable Forms Flaw Lets Attackers Pay Less For Expensive Purchases via @sejournal, @martinibuster
- ●A critical vulnerability in the Formidable Forms plugin allows unauthenticated attackers to bypass payment verification, affecting over 300,000 sites.
- ●The flaw, identified as CVE-2026-2890, enables attackers to exploit payment validation weaknesses by reusing Stripe PaymentIntents to authorize high-value transactions without genuine payment.
- ●WordPress users with the affected plugin are urged to update to version 6.29 or newer to secure their sites against this vulnerability.












