SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz
sureforms · plugin
Known security vulnerabilities for SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz. Find out in seconds which version runs on your site with WP Lens.
13 known vulnerabilities
10 exploitable without logging in · 3 with public exploit code · latest Sep 5, 2026
Listed on wordpress.org · latest 2.12.8 · last updated Sep 25, 2026 · 500K+ installs
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- High 8.1
CVE-2025-6691unauthenticated · needs a click≤ 1.7.3
SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission Deletion
- High 7.5
CVE-2026-15288unauthenticated≤ 2.2.1
SureForms – Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticated Stripe Payment Amount Manipulation
- High 7.5
CVE-2026-4987unauthenticated≤ 2.5.2
SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id'
- High 7.5
CVE-2025-6742unauthenticated · needs a click≤ 1.7.3
SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated PHP Object Injection (PHAR) Triggered via Admin Submission Deletion
- High 7.2
CVE-2026-18406unauthenticated≤ 2.12.2
SureForms <= 2.12.2 - Unauthenticated Stored Cross-Site Scripting via Text Field Entity-Encoded Payload
- High 7.2
CVE-2025-14855unauthenticated≤ 2.2.0
SureForms <= 2.2.0 - Unauthenticated Stored Cross-Site Scripting
- Medium 6.4
CVE-2026-7623contributor+≤ 2.8.1
SureForms <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'headingWrapper' Block Attribute
- Medium 5.3
CVE-2026-85308unauthenticated≤ 2.12.5
WordPress SureForms plugin <= 2.12.5 - Insecure Direct Object References (IDOR) vulnerability
- Medium 5.3
CVE-2025-12535unauthenticated≤ 1.13.1
SureForms <= 1.13.1 - Cross-Site Request Forgery Protection Bypass via Improper Nonce Distribution
- Medium 5.3
CVE-2025-12536unauthenticated≤ 1.13.1
SureForms <= 1.13.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure
- Medium 5.3
CVE-2024-12713unauthenticated≤ 1.2.2
SureForms – Drag and Drop Form Builder for WordPress <= 1.2.2 - Missing Authorization to Unauthenticated Protected Post Disclosure
- Medium 4.3
CVE-2025-10732contributor+≤ 1.12.1
SureForms – Drag and Drop Form Builder for WordPress <= 1.12.1 - Missing Authorization to Authenticated (Contributor+) Information Disclosure
- Medium 4.3
CVE-2025-10489contributor+≤ 1.12.0
SureForms – Drag and Drop Form Builder for WordPress <= 1.12.0 - Missing Authorization to Authenticated (Contributor+) Form Creation
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).