SureForms <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'headingWrapper' Block Attribute
medium
The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headingWrapper' parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att...
- CVSS:
- 6.4
- Affected:
- up to 2.8.1
- Fixed in:
- 2.8.2
- Disclosed:
- Jul 31, 2026
CVE-2026-7623 on NVD →
SureForms <= 2.11.0 - Unauthenticated Payment Amount Bypass
medium
The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Payment Amount Bypass in all versions up to, and including, 2.11.0. This makes it possible for unauthenticated attackers to pay less than is intended.
- CVSS:
- 5.3
- Affected:
- up to 2.11.0
- Fixed in:
- 2.11.1
- Disclosed:
- Jun 23, 2026
CVE-2026-11567 on NVD →
SureForms - Unauthenticated Payment Amount Validation Bypass via 'form_id' vulnerability
high
Unauthenticated Payment Amount Validation Bypass via 'form_id' vulnerability
- CVSS:
- 7.5
- Affected:
- up to 2.5.2
- Fixed in:
- 2.6.0
- Disclosed:
- Mar 30, 2026
SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id'
high
The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amount Bypass in all versions up to, and including, 2.5.2. This is due to the create_payment_intent() function performing a payment validation solely based on the value of a user-controlled parameter. Th...
- CVSS:
- 7.5
- Affected:
- up to 2.5.2
- Fixed in:
- 2.6.0
- Disclosed:
- Mar 27, 2026
CVE-2026-4987 on NVD →
SureForms <= 2.2.1 - Missing Authorization
medium
The SureForms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.2
- Disclosed:
- Feb 15, 2026
SureForms – Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticated Stripe Payment Amount Manipulation
high
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 2.2.1. This is due to the plugin accepting the payment amount directly from user-controlled POST data in the 'create_payment_intent' and 'create_subscription_int...
- CVSS:
- 7.5
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.2
- Disclosed:
- Feb 13, 2026
CVE-2026-15288 on NVD →
SureForms – Contact Form, Payment Form & Other Custom Form Builder [sureforms] < 2.2.1
unknown
[en] The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wi...
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.1
- Disclosed:
- Dec 21, 2025
CVE-2025-14855 on NVD →
SureForms <= 2.2.0 - Unauthenticated Stored Cross-Site Scripting
high
The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will ex...
- CVSS:
- 7.2
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.1
- Disclosed:
- Dec 20, 2025
CVE-2025-14855 on NVD →
SureForms – Contact Form, Payment Form & Other Custom Form Builder [sureforms] < 1.13.2
unknown
[en] The SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and including, 1.13.1. This is due to the plugin distributing generic WordPress REST API nonces (wp_rest) to unauthenticated users via the 'wp_ajax_nopriv_rest-nonce' action. While the plugin legitimately n...
- Affected:
- up to 1.13.2
- Fixed in:
- 1.13.2
- Disclosed:
- Nov 19, 2025
CVE-2025-12535 on NVD →
SureForms <= 1.13.1 - Cross-Site Request Forgery Protection Bypass via Improper Nonce Distribution
medium
The SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and including, 1.13.1. This is due to the plugin distributing generic WordPress REST API nonces (wp_rest) to unauthenticated users via the 'wp_ajax_nopriv_rest-nonce' action. While the plugin legitimately needs...
- CVSS:
- 5.3
- Affected:
- up to 1.13.1
- Fixed in:
- 1.13.2
- Disclosed:
- Nov 18, 2025
CVE-2025-12535 on NVD →
SureForms – Contact Form, Payment Form & Other Custom Form Builder [sureforms] < 1.13.2
unknown
[en] The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.1 via the '_srfm_email_notification' post meta registration. This is due to setting the 'auth_callback' parameter to '__return_true', which allows unauthenticated access to the metadata. Th...
- Affected:
- up to 1.13.2
- Fixed in:
- 1.13.2
- Disclosed:
- Nov 13, 2025
CVE-2025-12536 on NVD →
SureForms <= 1.13.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure
medium
The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.1 via the '_srfm_email_notification' post meta registration. This is due to setting the 'auth_callback' parameter to '__return_true', which allows unauthenticated access to the metadata. This ma...
- CVSS:
- 5.3
- Affected:
- up to 1.13.1
- Fixed in:
- 1.13.2
- Disclosed:
- Nov 12, 2025
CVE-2025-12536 on NVD →
SureForms – Contact Form, Payment Form & Other Custom Form Builder [sureforms] < 1.12.2
unknown
[en] The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.12.1. This is due to improper access control implementation on the '/wp-json/sureforms/v1/srfm-global-settings' REST API endpoint. This makes it po...
- Affected:
- up to 1.12.2
- Fixed in:
- 1.12.2
- Disclosed:
- Oct 14, 2025
CVE-2025-10732 on NVD →
SureForms – Drag and Drop Form Builder for WordPress <= 1.12.1 - Missing Authorization to Authenticated (Contributor+) Information Disclosure
medium
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.12.1. This is due to improper access control implementation on the '/wp-json/sureforms/v1/srfm-global-settings' REST API endpoint. This makes it possibl...
- CVSS:
- 4.3
- Affected:
- up to 1.12.1
- Fixed in:
- 1.12.2
- Disclosed:
- Oct 13, 2025
CVE-2025-10732 on NVD →
SureForms – Drag and Drop Form Builder for WordPress <= 1.12.0 - Missing Authorization to Authenticated (Contributor+) Form Creation
medium
The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to unauthorized creation of forms due to a missing capability check on the register_post_types() function in all versions up to, and including, 1.12.0. This makes it possible for authe...
- CVSS:
- 4.3
- Affected:
- up to 1.12.0
- Fixed in:
- 1.12.1
- Disclosed:
- Sep 19, 2025
CVE-2025-10489 on NVD →
SureForms – Drag and Drop Form Builder for WordPress <= 1.9.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping. This makes it possible for aut...
- CVSS:
- 4.4
- Affected:
- up to 1.9.0
- Fixed in:
- 1.9.1
- Disclosed:
- Sep 2, 2025
CVE-2025-8282 on NVD →
SureForms <= 1.7.1 - Reflected Cross-Site Scripting
medium
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...
- CVSS:
- 6.1
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Jul 11, 2025
CVE-2025-5921 on NVD →
SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission Deletion
high
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.7.3. This makes it possible for unauthenticated attackers to delete arbitrary files...
- CVSS:
- 8.1
- Affected:
- 0.0 – 0.0.13, 1.0 – 1.0.6, 1.1 – 1.1.1, 1.2 – 1.2.4, 1.3 – 1.3.1, 1.4 – 1.4.4, 1.5 – 1.5, 1.6 – 1.6.4, 1.7 – 1.7.3
- Fixed in:
- 0.0.14
- Disclosed:
- Jul 8, 2025
CVE-2025-6691 on NVD →
SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated PHP Object Injection (PHAR) Triggered via Admin Submission Deletion
high
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.3 via the use of file_exists() in the delete_entry_files() function without restriction on the path provided. This makes it possible for unauthenticated attackers...
- CVSS:
- 7.5
- Affected:
- 0.0 – 0.0.13, 1.0 – 1.0.6, 1.1 – 1.1.1, 1.2 – 1.2.4, 1.3 – 1.3.1, 1.4 – 1.4.4, 1.5 – 1.5, 1.6 – 1.6.4, 1.7 – 1.7.3
- Fixed in:
- 0.0.14
- Disclosed:
- Jul 8, 2025
CVE-2025-6742 on NVD →
SureForms <= 1.4.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-lev...
- CVSS:
- 4.4
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.4
- Disclosed:
- Apr 11, 2025
CVE-2025-3514 on NVD →
SureForms <= 1.4.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-lev...
- CVSS:
- 4.4
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.4
- Disclosed:
- Apr 11, 2025
CVE-2025-3513 on NVD →
SureForms – Drag and Drop Form Builder for WordPress <= 1.4.3 - Missing Authorization to Authenticated (Contributor+) Settings Update
medium
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the /sureforms/v1/srfm-global-settings REST Route in all versions up to, and including, 1.4.3. This makes it possible for authenticated attackers, with Contributor-leve...
- CVSS:
- 4.3
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.4
- Disclosed:
- Apr 9, 2025
CVE-2025-3471 on NVD →
SureForms – Contact Form, Payment Form & Other Custom Form Builder [sureforms] < 1.2.3
unknown
[en] The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the handle_export_form() function due to a missing capability check. This makes it possible for unauthenticated attackers to export data from password...
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.3
- Disclosed:
- Jan 8, 2025
CVE-2024-12713 on NVD →
SureForms – Drag and Drop Form Builder for WordPress <= 1.2.2 - Missing Authorization to Unauthenticated Protected Post Disclosure
medium
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the handle_export_form() function due to a missing capability check. This makes it possible for unauthenticated attackers to export data from password prote...
- CVSS:
- 5.3
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.3
- Disclosed:
- Jan 7, 2025
CVE-2024-12713 on NVD →
SureForms – Contact Form, Payment Form & Other Custom Form Builder [sureforms] <= 1.7.3 (unfixed)
unknown
- Affected:
- up to 1.7.3
- Fix:
- No patched version reported
CVE-2025-6691 on NVD →
SureForms – Contact Form, Payment Form & Other Custom Form Builder [sureforms] <= 1.7.3 (unfixed)
unknown
- Affected:
- up to 1.7.3
- Fix:
- No patched version reported
CVE-2025-6742 on NVD →
SureForms – Contact Form, Payment Form & Other Custom Form Builder [sureforms] < 1.7.2
unknown
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
CVE-2025-5921 on NVD →
SureForms – Contact Form, Payment Form & Other Custom Form Builder [sureforms] < 1.12.1
unknown
- Affected:
- up to 1.12.1
- Fixed in:
- 1.12.1
CVE-2025-10489 on NVD →
SureForms – Contact Form, Payment Form & Other Custom Form Builder [sureforms] < 1.4.4
unknown
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
CVE-2025-3471 on NVD →
SureForms – Contact Form, Payment Form & Other Custom Form Builder [sureforms] < 1.4.4
unknown
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
CVE-2025-3513 on NVD →
SureForms – Contact Form, Payment Form & Other Custom Form Builder [sureforms] < 1.4.4
unknown
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
CVE-2025-3514 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database