PT-2025-39146 · WordPress · Sureforms

Dmitry Ignatyev

·

Published

2025-09-23

·

Updated

2025-09-23

·

CVE-2025-8282

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SureForms WordPress plugin versions prior to 1.9.1
Description The SureForms WordPress plugin does not properly sanitize and escape parameters when displaying them on a page. This could allow administrators and users with higher privileges to carry out Cross-Site Scripting attacks.
Recommendations Update the SureForms WordPress plugin to version 1.9.1 or later.

Exploit

Fix

Related Identifiers

CVE-2025-8282

Affected Products

Sureforms