LOW🇬🇧 English

CVE-2025-3513

CVSS 3.5v3.1pub. 2025-05-02upd. 2025-05-28

Plugin SureForms dla WordPress w wersjach przed 1.4.4 nie sanityzuje i nie escapuje niektórych ustawień formularza, co mogłoby pozwolić użytkownikom o wysokim poziomie uprawnień, takim jak administrator, na przeprowadzenie ataków Stored XSS nawet gdy możliwość unfiltered_html jest zakazana (na przykład w konfiguracji multisite).

Pokaż oryginał (EN)

The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
  • Brainstormforce Sureforms

    APP
    Brainstormforce
    < 1.4.4
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
XSS
CWE
Referencje

Powiązane podatności

CVE-2025-6691HIGH8.1ten sam produkt

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file ...

CVE-2025-6742HIGH7.5ten sam produkt

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Inje...

CVE-2025-5921MEDIUM5.8ten sam produkt

The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it bac...

CVE-2025-3471MEDIUM4.9ten sam produkt

The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settin...

CVE-2024-12713MEDIUM5.3ten sam produkt

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exp...