SureForms – Drag and Drop Form Builder for WordPress <= 1.9.0 - Authenticated (Admin+) Stored Cross-Site Scripting
SureForms – Contact Form, Payment Form & Other Custom Form Builder
Minimum safe version
2.6.0
Update to 2.6.0 or later to address 16 fixable vulnerabilities
SureForms – Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticated Stripe Payment Amount Manipulation
SureForms <= 2.2.1 - Missing Authorization
SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id'
CVE-2025-14855
CVE-2025-12535
CVE-2025-12536
CVE-2025-10732
SureForms – Drag and Drop Form Builder for WordPress <= 1.12.0 - Missing Authorization to Authenticated (Contributor+) Form Creation
SureForms <= 1.7.1 - Reflected Cross-Site Scripting
SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated PHP Object Injection (PHAR) Triggered via Admin Submission Deletion
SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission Deletion
SureForms – Drag and Drop Form Builder for WordPress <= 1.4.3 - Missing Authorization to Authenticated (Contributor+) Settings Update
SureForms <= 1.4.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
SureForms <= 1.4.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
CVE-2024-12713