Back to Advanced Plugins

SureForms – Contact Form, Payment Form & Other Custom Form Builder

sureforms
300,000
Total Installs
12
Total Vulnerabilities
0
Critical
3
High
9
Medium
0
Low

Vulnerabilities (12)

SureForms <= 2.2.0 - Unauthenticated Stored Cross-Site Scripting
high Patched
CVSS Score 7.2
CWE CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Published Dec 20, 2025
The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
SureForms <= 1.13.1 - Cross-Site Request Forgery Protection Bypass via Improper Nonce Distribution
medium Patched
CVSS Score 5.3
CWE CWE-352: Cross-Site Request Forgery (CSRF)
Published Nov 18, 2025
The SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and including, 1.13.1. This is due to the plugin distributing generic WordPress REST API nonces (wp_rest) to unauthenticated users via the 'wp_ajax_nopriv_rest-nonce' action. While the plugin legitimately needs to support unauthenticated form submissions, it incorrectly uses generic REST nonces instead of form-specific nonces. This makes it possible for unauthenticated attackers to bypass CSRF protection on REST API endpoints that rely solely on nonce verification without additional authentication checks, allowing them to trigger unauthorized actions such as the plugin's own post-submission hooks and potentially other plugins' REST endpoints.
SureForms <= 1.13.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure
medium Patched
CVSS Score 5.3
CWE CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
Published Nov 12, 2025
The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.1 via the '_srfm_email_notification' post meta registration. This is due to setting the 'auth_callback' parameter to '__return_true', which allows unauthenticated access to the metadata. This makes it possible for unauthenticated attackers to extract sensitive data including email notification configurations, which frequently contain vendor-provided CRM/help desk dropbox addresses, CC/BCC recipients, and notification templates that can be abused to inject malicious data into downstream systems.
SureForms – Drag and Drop Form Builder for WordPress <= 1.12.1 - Missing Authorization to Authenticated (Contributor+) Information Disclosure
medium Patched
CVSS Score 4.3
CWE CWE-862: Missing Authorization
Published Oct 13, 2025
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.12.1. This is due to improper access control implementation on the '/wp-json/sureforms/v1/srfm-global-settings' REST API endpoint. This makes it possible for authenticated attackers, with contributor-level access and above, to retrieve sensitive information including API keys for Google reCAPTCHA, Cloudflare Turnstile, hCaptcha, admin email addresses, and security-related form settings.
SureForms – Drag and Drop Form Builder for WordPress <= 1.12.0 - Missing Authorization to Authenticated (Contributor+) Form Creation
medium Patched
CVSS Score 4.3
CWE CWE-862: Missing Authorization
Published Sep 19, 2025
The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to unauthorized creation of forms due to a missing capability check on the register_post_types() function in all versions up to, and including, 1.12.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to create forms when the user interface specifically prohibits it.
SureForms – Drag and Drop Form Builder for WordPress <= 1.9.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium Patched
CVE ID CVE-2025-8282
CVSS Score 4.4
CWE CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Published Sep 2, 2025
The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
SureForms <= 1.7.1 - Reflected Cross-Site Scripting
medium Patched
CVE ID CVE-2025-5921
CVSS Score 6.1
CWE CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Published Jul 11, 2025
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission Deletion
high Patched
CVE ID CVE-2025-6691
CVSS Score 8.1
CWE CWE-73: External Control of File Name or Path
Published Jul 8, 2025
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.7.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated PHP Object Injection (PHAR) Triggered via Admin Submission Deletion
high Patched
CVE ID CVE-2025-6742
CVSS Score 7.5
CWE CWE-502: Deserialization of Untrusted Data
Published Jul 8, 2025
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.3 via the use of file_exists() in the delete_entry_files() function without restriction on the path provided. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
SureForms <= 1.4.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium Patched
CVE ID CVE-2025-3514
CVSS Score 4.4
CWE CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Published Apr 11, 2025
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
SureForms <= 1.4.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium Patched
CVE ID CVE-2025-3513
CVSS Score 4.4
CWE CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Published Apr 11, 2025
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
SureForms – Drag and Drop Form Builder for WordPress <= 1.4.3 - Missing Authorization to Authenticated (Contributor+) Settings Update
medium Patched
CVE ID CVE-2025-3471
CVSS Score 4.3
CWE CWE-863: Incorrect Authorization
Published Apr 9, 2025
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the /sureforms/v1/srfm-global-settings REST Route in all versions up to, and including, 1.4.3. This makes it possible for authenticated attackers, with Contributor-level access and above, to update the plugin's settings.