plugin

Sureforms Vulnerabilities

31 known security issues reported for the Sureforms WordPress plugin. Most recent disclosed Jul 31, 2026.

6 high 13 medium

Running Sureforms on your site? Check whether your installed version is affected.

Scan your site free

SureForms <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'headingWrapper' Block Attribute

medium

The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headingWrapper' parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att...

CVSS:
6.4
Affected:
up to 2.8.1
Fixed in:
2.8.2
Disclosed:
Jul 31, 2026

CVE-2026-7623 on NVD →

SureForms <= 2.11.0 - Unauthenticated Payment Amount Bypass

medium

The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Payment Amount Bypass in all versions up to, and including, 2.11.0. This makes it possible for unauthenticated attackers to pay less than is intended.

CVSS:
5.3
Affected:
up to 2.11.0
Fixed in:
2.11.1
Disclosed:
Jun 23, 2026

CVE-2026-11567 on NVD →

SureForms - Unauthenticated Payment Amount Validation Bypass via 'form_id' vulnerability

high

Unauthenticated Payment Amount Validation Bypass via 'form_id' vulnerability

CVSS:
7.5
Affected:
up to 2.5.2
Fixed in:
2.6.0
Disclosed:
Mar 30, 2026

SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id'

high

The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amount Bypass in all versions up to, and including, 2.5.2. This is due to the create_payment_intent() function performing a payment validation solely based on the value of a user-controlled parameter. Th...

CVSS:
7.5
Affected:
up to 2.5.2
Fixed in:
2.6.0
Disclosed:
Mar 27, 2026

CVE-2026-4987 on NVD →

SureForms <= 2.2.1 - Missing Authorization

medium

The SureForms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.2.1
Fixed in:
2.2.2
Disclosed:
Feb 15, 2026

SureForms – Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticated Stripe Payment Amount Manipulation

high

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 2.2.1. This is due to the plugin accepting the payment amount directly from user-controlled POST data in the 'create_payment_intent' and 'create_subscription_int...

CVSS:
7.5
Affected:
up to 2.2.1
Fixed in:
2.2.2
Disclosed:
Feb 13, 2026

CVE-2026-15288 on NVD →

SureForms &#8211; Contact Form, Payment Form &amp; Other Custom Form Builder [sureforms] < 2.2.1

unknown

[en] The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wi...

Affected:
up to 2.2.1
Fixed in:
2.2.1
Disclosed:
Dec 21, 2025

CVE-2025-14855 on NVD →

SureForms <= 2.2.0 - Unauthenticated Stored Cross-Site Scripting

high

The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will ex...

CVSS:
7.2
Affected:
up to 2.2.0
Fixed in:
2.2.1
Disclosed:
Dec 20, 2025

CVE-2025-14855 on NVD →

SureForms &#8211; Contact Form, Payment Form &amp; Other Custom Form Builder [sureforms] < 1.13.2

unknown

[en] The SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and including, 1.13.1. This is due to the plugin distributing generic WordPress REST API nonces (wp_rest) to unauthenticated users via the 'wp_ajax_nopriv_rest-nonce' action. While the plugin legitimately n...

Affected:
up to 1.13.2
Fixed in:
1.13.2
Disclosed:
Nov 19, 2025

CVE-2025-12535 on NVD →

SureForms <= 1.13.1 - Cross-Site Request Forgery Protection Bypass via Improper Nonce Distribution

medium

The SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and including, 1.13.1. This is due to the plugin distributing generic WordPress REST API nonces (wp_rest) to unauthenticated users via the 'wp_ajax_nopriv_rest-nonce' action. While the plugin legitimately needs...

CVSS:
5.3
Affected:
up to 1.13.1
Fixed in:
1.13.2
Disclosed:
Nov 18, 2025

CVE-2025-12535 on NVD →

SureForms &#8211; Contact Form, Payment Form &amp; Other Custom Form Builder [sureforms] < 1.13.2

unknown

[en] The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.1 via the '_srfm_email_notification' post meta registration. This is due to setting the 'auth_callback' parameter to '__return_true', which allows unauthenticated access to the metadata. Th...

Affected:
up to 1.13.2
Fixed in:
1.13.2
Disclosed:
Nov 13, 2025

CVE-2025-12536 on NVD →

SureForms <= 1.13.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure

medium

The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.1 via the '_srfm_email_notification' post meta registration. This is due to setting the 'auth_callback' parameter to '__return_true', which allows unauthenticated access to the metadata. This ma...

CVSS:
5.3
Affected:
up to 1.13.1
Fixed in:
1.13.2
Disclosed:
Nov 12, 2025

CVE-2025-12536 on NVD →

SureForms &#8211; Contact Form, Payment Form &amp; Other Custom Form Builder [sureforms] < 1.12.2

unknown

[en] The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.12.1. This is due to improper access control implementation on the '/wp-json/sureforms/v1/srfm-global-settings' REST API endpoint. This makes it po...

Affected:
up to 1.12.2
Fixed in:
1.12.2
Disclosed:
Oct 14, 2025

CVE-2025-10732 on NVD →

SureForms – Drag and Drop Form Builder for WordPress <= 1.12.1 - Missing Authorization to Authenticated (Contributor+) Information Disclosure

medium

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.12.1. This is due to improper access control implementation on the '/wp-json/sureforms/v1/srfm-global-settings' REST API endpoint. This makes it possibl...

CVSS:
4.3
Affected:
up to 1.12.1
Fixed in:
1.12.2
Disclosed:
Oct 13, 2025

CVE-2025-10732 on NVD →

SureForms – Drag and Drop Form Builder for WordPress <= 1.12.0 - Missing Authorization to Authenticated (Contributor+) Form Creation

medium

The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to unauthorized creation of forms due to a missing capability check on the register_post_types() function in all versions up to, and including, 1.12.0. This makes it possible for authe...

CVSS:
4.3
Affected:
up to 1.12.0
Fixed in:
1.12.1
Disclosed:
Sep 19, 2025

CVE-2025-10489 on NVD →

SureForms – Drag and Drop Form Builder for WordPress <= 1.9.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping. This makes it possible for aut...

CVSS:
4.4
Affected:
up to 1.9.0
Fixed in:
1.9.1
Disclosed:
Sep 2, 2025

CVE-2025-8282 on NVD →

SureForms <= 1.7.1 - Reflected Cross-Site Scripting

medium

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...

CVSS:
6.1
Affected:
up to 1.7.1
Fixed in:
1.7.2
Disclosed:
Jul 11, 2025

CVE-2025-5921 on NVD →

SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission Deletion

high

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.7.3. This makes it possible for unauthenticated attackers to delete arbitrary files...

CVSS:
8.1
Affected:
0.0 – 0.0.13, 1.0 – 1.0.6, 1.1 – 1.1.1, 1.2 – 1.2.4, 1.3 – 1.3.1, 1.4 – 1.4.4, 1.5 – 1.5, 1.6 – 1.6.4, 1.7 – 1.7.3
Fixed in:
0.0.14
Disclosed:
Jul 8, 2025

CVE-2025-6691 on NVD →

SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated PHP Object Injection (PHAR) Triggered via Admin Submission Deletion

high

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.3 via the use of file_exists() in the delete_entry_files() function without restriction on the path provided. This makes it possible for unauthenticated attackers...

CVSS:
7.5
Affected:
0.0 – 0.0.13, 1.0 – 1.0.6, 1.1 – 1.1.1, 1.2 – 1.2.4, 1.3 – 1.3.1, 1.4 – 1.4.4, 1.5 – 1.5, 1.6 – 1.6.4, 1.7 – 1.7.3
Fixed in:
0.0.14
Disclosed:
Jul 8, 2025

CVE-2025-6742 on NVD →

SureForms <= 1.4.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-lev...

CVSS:
4.4
Affected:
up to 1.4.3
Fixed in:
1.4.4
Disclosed:
Apr 11, 2025

CVE-2025-3514 on NVD →

SureForms <= 1.4.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-lev...

CVSS:
4.4
Affected:
up to 1.4.3
Fixed in:
1.4.4
Disclosed:
Apr 11, 2025

CVE-2025-3513 on NVD →

SureForms – Drag and Drop Form Builder for WordPress <= 1.4.3 - Missing Authorization to Authenticated (Contributor+) Settings Update

medium

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the /sureforms/v1/srfm-global-settings REST Route in all versions up to, and including, 1.4.3. This makes it possible for authenticated attackers, with Contributor-leve...

CVSS:
4.3
Affected:
up to 1.4.3
Fixed in:
1.4.4
Disclosed:
Apr 9, 2025

CVE-2025-3471 on NVD →

SureForms &#8211; Contact Form, Payment Form &amp; Other Custom Form Builder [sureforms] < 1.2.3

unknown

[en] The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the handle_export_form() function due to a missing capability check. This makes it possible for unauthenticated attackers to export data from password...

Affected:
up to 1.2.3
Fixed in:
1.2.3
Disclosed:
Jan 8, 2025

CVE-2024-12713 on NVD →

SureForms – Drag and Drop Form Builder for WordPress <= 1.2.2 - Missing Authorization to Unauthenticated Protected Post Disclosure

medium

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the handle_export_form() function due to a missing capability check. This makes it possible for unauthenticated attackers to export data from password prote...

CVSS:
5.3
Affected:
up to 1.2.2
Fixed in:
1.2.3
Disclosed:
Jan 7, 2025

CVE-2024-12713 on NVD →

SureForms &#8211; Contact Form, Payment Form &amp; Other Custom Form Builder [sureforms] <= 1.7.3 (unfixed)

unknown
Affected:
up to 1.7.3
Fix:
No patched version reported

CVE-2025-6691 on NVD →

SureForms &#8211; Contact Form, Payment Form &amp; Other Custom Form Builder [sureforms] <= 1.7.3 (unfixed)

unknown
Affected:
up to 1.7.3
Fix:
No patched version reported

CVE-2025-6742 on NVD →

SureForms &#8211; Contact Form, Payment Form &amp; Other Custom Form Builder [sureforms] < 1.7.2

unknown
Affected:
up to 1.7.2
Fixed in:
1.7.2

CVE-2025-5921 on NVD →

SureForms &#8211; Contact Form, Payment Form &amp; Other Custom Form Builder [sureforms] < 1.12.1

unknown
Affected:
up to 1.12.1
Fixed in:
1.12.1

CVE-2025-10489 on NVD →

SureForms &#8211; Contact Form, Payment Form &amp; Other Custom Form Builder [sureforms] < 1.4.4

unknown
Affected:
up to 1.4.4
Fixed in:
1.4.4

CVE-2025-3471 on NVD →

SureForms &#8211; Contact Form, Payment Form &amp; Other Custom Form Builder [sureforms] < 1.4.4

unknown
Affected:
up to 1.4.4
Fixed in:
1.4.4

CVE-2025-3513 on NVD →

SureForms &#8211; Contact Form, Payment Form &amp; Other Custom Form Builder [sureforms] < 1.4.4

unknown
Affected:
up to 1.4.4
Fixed in:
1.4.4

CVE-2025-3514 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database