CVE-2024-12713

MEDIUM

SureForms < 1.2.3 - Unauthenticated Information Exposure via handle_export_form()

Title source: llm
STIX 2.1

Description

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the handle_export_form() function due to a missing capability check. This makes it possible for unauthenticated attackers to export data from password protected, private, or draft posts that they should not have access to.

Scores

CVSS v3 5.3
EPSS 0.0033
EPSS Percentile 24.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
brainstormforce/sureforms < 1.2.3
brainstormforce/SureForms – Contact Form, Payment Form & Other Custom Form Builder < 1.2.2
Published Jan 08, 2025
Tracked Since Feb 18, 2026