PT-2025-38631 · WordPress · Sureforms

Jessie Irelan

·

Published

2025-09-20

·

Updated

2025-09-20

·

CVE-2025-10489

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress versions through 1.12.0
Description The SureForms plugin for WordPress is susceptible to unauthorized form creation due to a missing capability check within the register post types() function. This allows authenticated attackers with Contributor-level access or higher to create forms, even when the user interface restricts this action.
Recommendations Update to a version beyond 1.12.0.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-10489

Affected Products

Sureforms