PT-2026-57065 · Brainstorm Force+1 · Sureforms – Drag & Drop Contact Form & Form Builder+1

·

CVE-2026-15288

·

Published

2026-02-13

·

Updated

2026-07-10

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions SureForms – Drag and Drop Form Builder for WordPress versions prior to 2.2.2
Description Improper Input Validation occurs because the plugin accepts payment amounts directly from user-controlled POST data within the create payment intent() and create subscription intent() functions without validating them against the configured price of the form. This allows unauthenticated attackers to modify the payment amount to an arbitrary value during Stripe payment form submission, potentially enabling the purchase of products or services at reduced prices.
Recommendations Update SureForms – Drag and Drop Form Builder for WordPress to version 2.2.2 or later. As a temporary workaround, restrict access to the create payment intent() and create subscription intent() functions.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15288

Affected Products

Sureforms – Drag & Drop Contact Form & Form Builder
Sureforms