CVE · Medium

CVE-2025-12536 — SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz [sureforms] < 1.13.2

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2025-12536 SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz [sureforms] < 1.13.2 Exposición de información personal privada a un actor no autorizado Media 5,3 < 1.13.2 1.13.2 2025-11-12

CVE-2025-12536

The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.1 via the '_srfm_email_notification' post meta registration. This is due to setting the 'auth_callback' parameter to '__return_true', which allows unauthenticated access to the metadata. This makes it possible for unauthenticated attackers to extract sensitive data including email notification configurations, which frequently contain vendor-provided CRM/help desk dropbox addresses, CC/BCC recipients, and notification templates that can be abused to inject malicious data into downstream systems.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Escanea tu sitio WordPress gratis

Sin registro, sin tarjeta de crédito — ingresa tu URL y obtén un informe de seguridad en segundos.