HIGH🇵🇱 Wersja polska

CVE-2025-6691

CVSS 8.1v3.1pub. 2025-07-09upd. 2025-07-11

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.7.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
  • Brainstormforce Sureforms

    APP
    Brainstormforce
    1.5.01.0.0 – 1.0.7 (excl.)1.1.0 – 1.1.2 (excl.)1.2.0 – 1.2.5 (excl.)0.0.2 – 0.0.14 (excl.)1.4.0 – 1.4.5 (excl.)1.6.0 – 1.6.5 (excl.)1.7.0 – 1.7.4 (excl.)1.3.0 – 1.3.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEAuth Bypass
CWE
References

Related vulnerabilities

CVE-2025-6742HIGH7.5same product

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Inje...

CVE-2025-5921MEDIUM5.8same product

The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it bac...

CVE-2025-3471MEDIUM4.9same product

The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settin...

CVE-2024-12713MEDIUM5.3same product

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exp...

CVE-2025-3513LOW3.5same product

Plugin SureForms dla WordPress w wersjach przed 1.4.4 nie sanityzuje i nie escapuje niektórych ustawień formul...