PT-2025-18233 · WordPress · Sureforms

Dmitry Ignatyev

·

Published

2025-04-30

·

Updated

2025-04-30

·

CVE-2025-3471

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions SureForms WordPress plugin versions prior to 1.4.4
Description The issue concerns a lack of proper authorization checks when updating settings via the REST API, potentially allowing Contributor and above roles to perform such actions.
Recommendations For versions prior to 1.4.4, update to version 1.4.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the REST API for Contributor and above roles until the update is applied.

Exploit

Fix

Related Identifiers

CVE-2025-3471

Affected Products

Sureforms