brainstormforce Vulnerabilities and Affected Products
Vulnerabilities associated with SureForms – Contact Form, Payment Form & Other Custom Form Builder.
Products
Clear product- Spectra Gutenberg Blocks – Website Builder for the Block Editor11 vulnerabilities
- Ultimate Addons for Elementor10 vulnerabilities
- SureForms – Contact Form, Payment Form & Other Custom Form Builder7 vulnerabilities
- Ultimate Addons for Beaver Builder – Lite5 vulnerabilities
- CartFlows – Funnel Builder & Checkout Plugin for WooCommerce3 vulnerabilities
- Starter Templates – AI-Powered Templates for Elementor & Gutenberg3 vulnerabilities
- ultimate_addons_for_elementor3 vulnerabilities
- Astra2 vulnerabilities
- Custom Fonts – Host Your Fonts Locally2 vulnerabilities
- OttoKit: All-in-One Automation Platform2 vulnerabilities
- spectra2 vulnerabilities
- SureForms – Drag and Drop Form Builder for WordPress2 vulnerabilities
- convertplug1 vulnerability
- Import / Export Customizer Settings1 vulnerability
- Lightweight Sidebar Manager1 vulnerability
- Spectra Legacy – Gutenberg Blocks1 vulnerability
- spectra_pro1 vulnerability
- Starter Templates — Elementor, Gutenberg & Beaver Builder Templates1 vulnerability
- starter_templates1 vulnerability
- Surecart1 vulnerability
- SureDash – Community, Courses & Member Dashboard1 vulnerability
- SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz1 vulnerability
- SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator1 vulnerability
- SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers1 vulnerability
- ultimate_addons_for_wpbakery_page_builder1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-4987HIGH | SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id'The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amount Bypass in all versions up to, and including, 2.5.2. This is due to the create_payment_intent() function performing a payment validation solely based on the value of a user-controlled parameter. This makes it possible for unauthenticated attackers to bypass configured form payment-amount validation and create underpriced payment/subscription intents by setting form_id to 0. | CVSS7.5v3.1 | EPSS0.707% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2025-14855HIGH | SureForms <= 2.2.0 - Unauthenticated Stored Cross-Site ScriptingThe SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79Dec 21, 2025 | CVSS7.2v3.1 | EPSS0.331% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-12535MEDIUM | SureForms <= 1.13.1 - Cross-Site Request Forgery Protection Bypass via Improper Nonce DistributionThe SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and including, 1.13.1. This is due to the plugin distributing generic WordPress REST API nonces (wp_rest) to unauthenticated users via the 'wp_ajax_nopriv_rest-nonce' action. While the plugin legitimately needs to support unauthenticated form submissions, it incorrectly uses generic REST nonces instead of form-specific nonces. This makes it possible for unauthenticated attackers to bypass… CWE-352Nov 19, 2025 | CVSS5.3v3.1 | EPSS0.202% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-12536MEDIUM | SureForms <= 1.13.1 - Missing Authorization to Unauthenticated Sensitive Information ExposureThe SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.1 via the '_srfm_email_notification' post meta registration. This is due to setting the 'auth_callback' parameter to '__return_true', which allows unauthenticated access to the metadata. This makes it possible for unauthenticated attackers to extract sensitive data including email notification configurations, which frequently contain vendor-provided CRM/help desk dropbox … | CVSS5.3v3.1 | EPSS0.797% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2025-10732MEDIUM | SureForms – Drag and Drop Form Builder for WordPress <= 1.12.1 - Missing Authorization to Authenticated (Contributor+) Information DisclosureThe SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.12.1. This is due to improper access control implementation on the '/wp-json/sureforms/v1/srfm-global-settings' REST API endpoint. This makes it possible for authenticated attackers, with contributor-level access and above, to retrieve sensitive information including API keys for Google reCAPTCHA, Cloudflare Turnstile, hCaptcha, a… CWE-862Oct 14, 2025 | CVSS4.3v3.1 | EPSS0.237% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-10489MEDIUM | SureForms – Drag and Drop Form Builder for WordPress <= 1.12.0 - Missing Authorization to Authenticated (Contributor+) Form CreationThe SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to unauthorized creation of forms due to a missing capability check on the register_post_types() function in all versions up to, and including, 1.12.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to create forms when the user interface specifically prohibits it. CWE-862Sep 20, 2025 | CVSS4.3v3.1 | EPSS0.182% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-12713MEDIUM | SureForms – Drag and Drop Form Builder for WordPress <= 1.2.2 - Missing Authorization to Unauthenticated Protected Post DisclosureThe SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the handle_export_form() function due to a missing capability check. This makes it possible for unauthenticated attackers to export data from password protected, private, or draft posts that they should not have access to. CWE-862Jan 8, 2025 | CVSS5.3v3.1 | EPSS0.343% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |