MEDIUM🇵🇱 Wersja polska

CVE-2025-3471

CVSS 4.9v3.1pub. 2025-04-30upd. 2025-05-09

The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to perform such action

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
  • Brainstormforce Sureforms

    APP
    Brainstormforce
    < 1.4.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-6691HIGH8.1same product

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file ...

CVE-2025-6742HIGH7.5same product

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Inje...

CVE-2025-5921MEDIUM5.8same product

The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it bac...

CVE-2024-12713MEDIUM5.3same product

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exp...

CVE-2025-3513LOW3.5same product

Plugin SureForms dla WordPress w wersjach przed 1.4.4 nie sanityzuje i nie escapuje niektórych ustawień formul...