The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to unauthorized creation of forms due to a missing capability check on the register_post_types() function in all versions up to, and including, 1.12.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to create forms when the user interface specifically prohibits it.
Metrics
Affected Vendors & Products
References
History
Mon, 22 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Sep 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brainstormforce
Brainstormforce sureforms Wordpress Wordpress wordpress |
|
| Vendors & Products |
Brainstormforce
Brainstormforce sureforms Wordpress Wordpress wordpress |
Sat, 20 Sep 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to unauthorized creation of forms due to a missing capability check on the register_post_types() function in all versions up to, and including, 1.12.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to create forms when the user interface specifically prohibits it. | |
| Title | SureForms – Drag and Drop Form Builder for WordPress <= 1.12.0 - Missing Authorization to Authenticated (Contributor+) Form Creation | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-09-20T04:27:55.370Z
Updated: 2025-09-22T15:10:15.514Z
Reserved: 2025-09-15T15:14:26.747Z
Link: CVE-2025-10489
Updated: 2025-09-22T15:10:08.368Z
Status : Awaiting Analysis
Published: 2025-09-20T05:15:35.657
Modified: 2025-09-22T21:23:01.543
Link: CVE-2025-10489
No data.