Skip to content
Noroxi

SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz

sureforms · plugin

Known security vulnerabilities for SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz. Find out in seconds which version runs on your site with WP Lens.

13 known vulnerabilities

10 exploitable without logging in · 3 with public exploit code · latest Sep 5, 2026

Listed on wordpress.org · latest 2.12.8 · last updated Sep 25, 2026 · 500K+ installs

wordpress.org status checked on Oct 2, 2026

Vulnerabilities

  • CVE-2025-6691unauthenticated · needs a click≤ 1.7.3

    SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission Deletion

    High 8.1
  • CVE-2026-15288unauthenticated≤ 2.2.1

    SureForms – Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticated Stripe Payment Amount Manipulation

    High 7.5
  • CVE-2026-4987unauthenticated≤ 2.5.2

    SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id'

    High 7.5
  • CVE-2025-6742unauthenticated · needs a click≤ 1.7.3

    SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated PHP Object Injection (PHAR) Triggered via Admin Submission Deletion

    High 7.5
  • CVE-2026-18406unauthenticated≤ 2.12.2

    SureForms <= 2.12.2 - Unauthenticated Stored Cross-Site Scripting via Text Field Entity-Encoded Payload

    High 7.2
  • CVE-2025-14855unauthenticated≤ 2.2.0

    SureForms <= 2.2.0 - Unauthenticated Stored Cross-Site Scripting

    High 7.2
  • CVE-2026-7623contributor+≤ 2.8.1

    SureForms <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'headingWrapper' Block Attribute

    Medium 6.4
  • CVE-2026-85308unauthenticated≤ 2.12.5

    WordPress SureForms plugin <= 2.12.5 - Insecure Direct Object References (IDOR) vulnerability

    Medium 5.3
  • CVE-2025-12535unauthenticated≤ 1.13.1

    SureForms <= 1.13.1 - Cross-Site Request Forgery Protection Bypass via Improper Nonce Distribution

    Medium 5.3
  • CVE-2025-12536unauthenticated≤ 1.13.1

    SureForms <= 1.13.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure

    Medium 5.3
  • CVE-2024-12713unauthenticated≤ 1.2.2

    SureForms – Drag and Drop Form Builder for WordPress <= 1.2.2 - Missing Authorization to Unauthenticated Protected Post Disclosure

    Medium 5.3
  • CVE-2025-10732contributor+≤ 1.12.1

    SureForms – Drag and Drop Form Builder for WordPress <= 1.12.1 - Missing Authorization to Authenticated (Contributor+) Information Disclosure

    Medium 4.3
  • CVE-2025-10489contributor+≤ 1.12.0

    SureForms – Drag and Drop Form Builder for WordPress <= 1.12.0 - Missing Authorization to Authenticated (Contributor+) Form Creation

    Medium 4.3

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory