PT-2025-41848 · WordPress · Sureforms – Drag/Drop Form Builder For Wordpress

Abu Hurayra

·

Published

2025-10-14

·

Updated

2025-10-14

·

CVE-2025-10732

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SureForms – Drag and Drop Form Builder for WordPress versions prior to 1.12.2
Description The SureForms – Drag and Drop Form Builder for WordPress plugin contains a flaw in access control. Specifically, the '/wp-json/sureforms/v1/srfm-global-settings' API endpoint does not properly restrict access. This allows authenticated attackers with contributor-level access or higher to obtain sensitive information. This information includes API keys for Google reCAPTCHA, Cloudflare Turnstile, and hCaptcha, as well as admin email addresses and security-related form settings.
Recommendations Update SureForms – Drag and Drop Form Builder for WordPress to version 1.12.2 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-10732

Affected Products

Sureforms – Drag/Drop Form Builder For Wordpress