PT-2026-28706 · WordPress · Sureforms+1

Jack Pas

·

Publicado

2026-03-28

·

Atualizado

2026-03-29

·

CVE-2026-4987

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress versions up to and including 2.5.2
Description The SureForms plugin is susceptible to a Payment Amount Bypass issue. This occurs because the create payment intent() function relies on a user-controlled parameter for payment validation. This allows unauthenticated attackers to circumvent payment amount validation and create underpriced payment or subscription intents by setting the form id parameter to 0.
Recommendations Update SureForms to a version later than 2.5.2

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-4987

Produtos afetados

Sureforms
Wordpress