Mollie Forms

Mollie Forms has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 4 are fixed as of September 2026. Their average CVSS score is 4.8, and the most serious one scores 6.4 out of 10. 2024 was the busiest year with 3 disclosures.

The most common weakness is Missing Authorization, behind 2 of the records (50%). Other recurring categories include Cross-Site Request Forgery (CSRF), Cross-Site Scripting.

Every one of the 4 issues recorded for Mollie Forms has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, most of them (3) reported by Lucio Sá. Mollie Forms is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
4.8/ 10
Patch Coverage100%
Open

0

Fixed

4

Get automatic notifications for all Mollie Forms vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2025-47502

Mollie Forms <= 2.7.12 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

4 records
Mollie Forms banner
Latestv2.11.0
4.1(19)
82/100
Last Updated
2026-08-19 (24d ago)
Active Installs
3,000+
Downloads
143,007
Requires WP
6.0+
Requires PHP
8.0+
Tested up to
WP 6.9.7
Created
2017-01-03 (10y ago)

Create registration forms with payment methods of Mollie. One-time and recurring payments are possible. Features: Create your own forms Set extra fee’s per payment method One-time and recurring payments Fixed or open amount possible Multicurrency Configure emails per form Refund payments and cancel subscriptions in WordPress admin Style it with your own css classes. Discount codes Shipping costs, with the option to set different shipping costs per country 3rd Party Services The plugin is using: the API of Mollie to create payments. the API of Google reCAPTCHA to prevent spam (if enabled) the API of Cloudflare Turnstile to prevent spam (if enabled)

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C