Brainstormforce Sureforms vulnerabilities
7 known vulnerabilities affecting brainstormforce/sureforms.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM3LOW2
Vulnerabilities
Page 1 of 1
CVE-2025-5921MEDIUMCVSS 5.8fixed in 1.7.22025-08-01
CVE-2025-5921 [MEDIUM] CWE-79 CVE-2025-5921: The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputt
The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both authenticated and unauthenticated users.
nvd
CVE-2025-6742HIGHCVSS 7.5≥ 0.0.2, < 0.0.14≥ 1.0.0, < 1.0.7+7 more2025-07-09
CVE-2025-6742 [HIGH] CWE-502 CVE-2025-6742: The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP O
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.3 via the use of file_exists() in the delete_entry_files() function without restriction on the path provided. This makes it possible for unauthenticated attackers to inject a PHP Object. No known P
nvd
CVE-2025-6691HIGHCVSS 8.1≥ 0.0.2, < 0.0.14≥ 1.0.0, < 1.0.7+7 more2025-07-09
CVE-2025-6691 [HIGH] CWE-73 CVE-2025-6691: The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbit
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.7.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lea
nvd
CVE-2025-3514LOWCVSS 3.5fixed in 1.4.42025-05-02
CVE-2025-3514 [LOW] CWE-79 CVE-2025-3514: The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings,
The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
nvd
CVE-2025-3513LOWCVSS 3.5fixed in 1.4.42025-05-02
CVE-2025-3513 [LOW] CWE-79 CVE-2025-3513: The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings,
The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
nvd
CVE-2025-3471MEDIUMCVSS 4.9fixed in 1.4.42025-04-30
CVE-2025-3471 [MEDIUM] CWE-863 CVE-2025-3471: The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating
The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to perform such action
nvd
CVE-2024-12713MEDIUMCVSS 5.3fixed in 1.2.32025-01-08
CVE-2024-12713 [MEDIUM] CWE-862 CVE-2024-12713: The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Infor
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the handle_export_form() function due to a missing capability check. This makes it possible for unauthenticated attackers to export data from password protected, private, or draft posts t
nvd