Mollie Forms Security & Risk Analysis

wordpress.org/plugins/mollie-forms

Create registration forms with payment methods of Mollie. One-time and recurring payments are possible.

3K active installs v2.9.3 PHP 8.0+ WP 6.0+ Updated Apr 9, 2026
formsidealpaymentsrecurringsubscriptions
97
A · Safe
CVEs total4
Unpatched0
Last CVEMay 7, 2025
Download
Safety Verdict

Is Mollie Forms Safe to Use in 2026?

Generally Safe

Score 97/100

Mollie Forms has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

4 known CVEsLast CVE: May 7, 2025Updated 1mo ago
Risk Assessment

The mollie-forms plugin version 2.9.2 presents a mixed security profile. On the positive side, it demonstrates good practices with a high percentage of SQL queries using prepared statements and properly escaped output. The absence of unauthenticated AJAX handlers and REST API routes is also a strong indicator of security awareness. Nonce and capability checks are present, mitigating some common attack vectors.

However, the static analysis reveals several areas of concern. The presence of 5 flows with unsanitized paths, all flagged as high severity taint analysis findings, is a significant red flag. These flows, if exploited, could lead to serious security breaches. While there are no unpatched CVEs currently, the plugin has a history of 4 medium-severity vulnerabilities, including Cross-Site Scripting, Cross-Site Request Forgery, and Missing Authorization. This historical pattern, coupled with the high-severity taint flows, suggests potential for recurring or new vulnerabilities if input validation and sanitization are not rigorously maintained.

Overall, while the plugin has implemented several security best practices, the high-severity taint flows and historical vulnerability trends warrant a cautious approach. The plugin's strengths lie in its SQL and output handling, but the identified taint issues and past CVEs highlight the need for ongoing vigilance and thorough security auditing of its input processing mechanisms.

Key Concerns

  • High severity unsanitized taint flows (5)
  • Medium severity CVE history (4)
  • File operations detected
  • External HTTP requests detected
Vulnerabilities
4 published

Mollie Forms Security Vulnerabilities

CVEs by Year

3 CVEs in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
4

4 total CVEs

CVE-2025-47502medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Mollie Forms <= 2.7.12 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 7, 2025 Patched in 2.7.13 (7d)
CVE-2024-2368medium · 4.3Cross-Site Request Forgery (CSRF)

Mollie Forms <= 2.6.13 - Cross-Site Request Forgery to Arbitrary Post Duplication

Jun 4, 2024 Patched in 2.6.14 (56d)
CVE-2024-1645medium · 4.3Missing Authorization

Mollie Forms <= 2.6.3 - Missing Authorization

Mar 11, 2024 Patched in 2.6.4 (1d)
CVE-2024-1400medium · 4.3Missing Authorization

Mollie Forms <= 2.6.3 - Missing Authorization to Arbitrary Post Duplication

Mar 11, 2024 Patched in 2.6.4 (1d)
Version History

Mollie Forms Release Timeline

v2.9.3Current
v2.9.2
v2.9.1
v2.9.0
v2.8.1
v2.8.0
v2.7.13
v2.7.121 CVE
v2.7.111 CVE
v2.7.101 CVE
v2.7.91 CVE
v2.7.81 CVE
v2.7.71 CVE
v2.7.61 CVE
v2.7.51 CVE
v2.7.41 CVE
v2.7.31 CVE
v2.7.21 CVE
v2.7.11 CVE
v2.7.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Mollie Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
21
65 prepared
Unescaped Output
9
571 escaped
Nonce Checks
14
Capability Checks
3
File Operations
1
External Requests
2
Bundled Libraries
0

SQL Query Safety

76% prepared86 total queries

Output Escaping

98% escaped580 total outputs
Data Flows · Security
5 unsanitized

Data Flow Analysis

12 flows5 with unsanitized paths
pageRegistrations (classes\Admin.php:669)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Mollie Forms Attack Surface

Entry Points6
Unprotected0

Shortcodes 6

[rfmp] classes\Form.php:34
[mollie-forms] classes\Form.php:35
[rfmp-total] classes\Form.php:36
[mollie-forms-total] classes\Form.php:37
[rfmp-goal] classes\Form.php:38
[mollie-forms-goal] classes\Form.php:39
WordPress Hooks 15
actioninitclasses\Admin.php:31
actionadmin_menuclasses\Admin.php:34
actionadmin_enqueue_scriptsclasses\Admin.php:35
actionadd_meta_boxes_mollie-formsclasses\Admin.php:36
actionsave_post_mollie-formsclasses\Admin.php:37
actionadmin_post_mollie-forms_exportclasses\Admin.php:38
actionadmin_post_mollie-forms_duplicateclasses\Admin.php:39
filterplugin_row_metaclasses\Admin.php:41
filterpost_row_actionsclasses\Admin.php:42
actionadmin_noticesclasses\Admin.php:44
filterupload_dirclasses\Form.php:580
actioninitclasses\MollieForms.php:183
filterquery_varsclasses\Webhook.php:26
actionparse_requestclasses\Webhook.php:27
actioninitclasses\Webhook.php:28
Maintenance & Trust

Mollie Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 9, 2026
PHP min version8.0
Downloads135K

Community Trust

Rating82/100
Number of ratings19
Active installs3K
Developer Profile

Mollie Forms Developer Profile

Nick van Wobbie

2 plugins · 7K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
168 days
View full developer profile
Detection Fingerprints

How We Detect Mollie Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mollie-forms/includes/js/admin-scripts.js/wp-content/plugins/mollie-forms/includes/css/admin-styles.css/wp-content/plugins/mollie-forms/includes/css/jquery-ui.css
Script Paths
/wp-content/plugins/mollie-forms/includes/js/admin-scripts.js
Version Parameters
mollie-forms/includes/js/admin-scripts.js?ver=mollie-forms/includes/css/admin-styles.css?ver=mollie-forms/includes/css/jquery-ui.css?ver=

HTML / DOM Fingerprints

CSS Classes
mf_recaptcha_v3_site_keymf_recaptcha_v3_secret_key
Data Attributes
data-mollie-forms-iddata-mollie-forms-field-id
JS Globals
rfmp_i18n
Shortcode Output
[mollie-forms id="
FAQ

Frequently Asked Questions about Mollie Forms