The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to unauthorized creation of forms due to a missing capability check on the register_post_types() function in all versions up to, and including, 1.12.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to create forms when the user interface specifically prohibits it.
Metrics
Affected Vendors & Products
References
History
Mon, 22 Sep 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 22 Sep 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Brainstormforce
Brainstormforce sureforms Wordpress Wordpress wordpress |
|
Vendors & Products |
Brainstormforce
Brainstormforce sureforms Wordpress Wordpress wordpress |
Sat, 20 Sep 2025 04:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to unauthorized creation of forms due to a missing capability check on the register_post_types() function in all versions up to, and including, 1.12.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to create forms when the user interface specifically prohibits it. | |
Title | SureForms – Drag and Drop Form Builder for WordPress <= 1.12.0 - Missing Authorization to Authenticated (Contributor+) Form Creation | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-09-20T04:27:55.370Z
Updated: 2025-09-22T15:10:15.514Z
Reserved: 2025-09-15T15:14:26.747Z
Link: CVE-2025-10489

Updated: 2025-09-22T15:10:08.368Z

Status : Awaiting Analysis
Published: 2025-09-20T05:15:35.657
Modified: 2025-09-22T21:23:01.543
Link: CVE-2025-10489

No data.