Extension WordPress

Vulnérabilités SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

Cette page rassemble les failles publiées pour SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator, leurs plages de versions affectées et les correctifs signalés dans la base locale.

16Vulnérabilités
0Critiques
16Avec correctif
8,1CVSS maximal

Historique de sécurité

CVE et vulnérabilités de SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

16 fiches

CVE-2026-4987 Élevée · 7,5
SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

SureForms <= 2.5.2 – Unauthenticated Payment Amount Validation Bypass via 'form_id'

The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amount Bypass in all versions up to, and including, 2.5.2. This is due to the create_payment_intent() function performing a…

Versions affectées

*-2.5.2

Correctif

2.6.0

Publication

27/03/2026

Vulnérabilité Moyenne · 5,3
SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

SureForms <= 2.2.1 – Missing Authorization

The SureForms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Versions affectées

*-2.2.1

Correctif

2.2.2

Publication

15/02/2026

CVE-2026-15288 Élevée · 7,5
SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

SureForms – Drag and Drop Form Builder for WordPress <= 2.2.1 – Unauthenticated Stripe Payment Amount Manipulation

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 2.2.1. This is due to the plugin accepting the payment amount directly…

Versions affectées

*-2.2.1

Correctif

2.2.2

Publication

13/02/2026

CVE-2025-14855 Élevée · 7,2
SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

SureForms <= 2.2.0 – Unauthenticated Stored Cross-Site Scripting

The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

*-2.2.0

Correctif

2.2.1

Publication

20/12/2025

CVE-2025-12535 Moyenne · 5,3
SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

SureForms <= 1.13.1 – Cross-Site Request Forgery Protection Bypass via Improper Nonce Distribution

The SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and including, 1.13.1. This is due to the plugin distributing generic WordPress REST API nonces (wp_rest) to unauthenticated users via the…

Versions affectées

*-1.13.1

Correctif

1.13.2

Publication

18/11/2025

CVE-2025-12536 Moyenne · 5,3
SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

SureForms <= 1.13.1 – Missing Authorization to Unauthenticated Sensitive Information Exposure

The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.1 via the '_srfm_email_notification' post meta registration. This is due to setting the 'auth_callback' parameter to '__return_true', which allows unauthenticated…

Versions affectées

*-1.13.1

Correctif

1.13.2

Publication

12/11/2025

CVE-2025-10732 Moyenne · 4,3
SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

SureForms – Drag and Drop Form Builder for WordPress <= 1.12.1 – Missing Authorization to Authenticated (Contributor+) Information Disclosure

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.12.1. This is due to improper access control implementation on the '/wp-json/sureforms/v1/srfm-global-settings'…

Versions affectées

*-1.12.1

Correctif

1.12.2

Publication

13/10/2025

CVE-2025-10489 Moyenne · 4,3
SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

SureForms – Drag and Drop Form Builder for WordPress <= 1.12.0 – Missing Authorization to Authenticated (Contributor+) Form Creation

The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to unauthorized creation of forms due to a missing capability check on the register_post_types() function in all…

Versions affectées

*-1.12.0

Correctif

1.12.1

Publication

19/09/2025

CVE-2025-8282 Moyenne · 4,4
SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

SureForms – Drag and Drop Form Builder for WordPress <= 1.9.0 – Authenticated (Admin+) Stored Cross-Site Scripting

The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.0 due to…

Versions affectées

*-1.9.0

Correctif

1.9.1

Publication

02/09/2025

CVE-2025-5921 Moyenne · 6,1
SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

SureForms <= 1.7.1 – Reflected Cross-Site Scripting

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-1.7.1

Correctif

1.7.2

Publication

11/07/2025

CVE-2025-6691 Élevée · 8,1
SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 – Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission Deletion

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.7.3. This…

Versions affectées

0.0-0.0.13, 1.0-1.0.6, 1.1-1.1.1, 1.2-1.2.4, 1.3-1.3.1, 1.4-1.4.4, 1.5, 1.6-1.6.4, 1.7-1.7.3

Correctif

0.0.14, 1.0.7, 1.1.2, 1.2.5, 1.3.2, 1.4.5, 1.5.1, 1.6.5, 1.7.4

Publication

08/07/2025

CVE-2025-6742 Élevée · 7,5
SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 – Unauthenticated PHP Object Injection (PHAR) Triggered via Admin Submission Deletion

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.3 via the use of file_exists() in the delete_entry_files() function without restriction…

Versions affectées

0.0-0.0.13, 1.0-1.0.6, 1.1-1.1.1, 1.2-1.2.4, 1.3-1.3.1, 1.4-1.4.4, 1.5, 1.6-1.6.4, 1.7-1.7.3

Correctif

0.0.14, 1.0.7, 1.1.2, 1.2.5, 1.3.2, 1.4.5, 1.5.1, 1.6.5, 1.7.4

Publication

08/07/2025

CVE-2025-3514 Moyenne · 4,4
SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

SureForms <= 1.4.3 – Authenticated (Administrator+) Stored Cross-Site Scripting

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping.…

Versions affectées

*-1.4.3

Correctif

1.4.4

Publication

11/04/2025

CVE-2025-3513 Moyenne · 4,4
SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

SureForms <= 1.4.3 – Authenticated (Administrator+) Stored Cross-Site Scripting

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping.…

Versions affectées

*-1.4.3

Correctif

1.4.4

Publication

11/04/2025

CVE-2025-3471 Moyenne · 4,3
SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

SureForms – Drag and Drop Form Builder for WordPress <= 1.4.3 – Missing Authorization to Authenticated (Contributor+) Settings Update

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the /sureforms/v1/srfm-global-settings REST Route in all versions up to, and including, 1.4.3. This…

Versions affectées

*-1.4.3

Correctif

1.4.4

Publication

09/04/2025

CVE-2024-12713 Moyenne · 5,3
SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

SureForms – Drag and Drop Form Builder for WordPress <= 1.2.2 – Missing Authorization to Unauthenticated Protected Post Disclosure

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the handle_export_form() function due to a missing capability check. This makes…

Versions affectées

*-1.2.2

Correctif

1.2.3

Publication

07/01/2025

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités