PT-2026-57065 · Brainstorm Force+1 · Sureforms – Drag & Drop Contact Form & Form Builder+1
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SureForms – Drag and Drop Form Builder for WordPress versions prior to 2.2.2
Description
Improper Input Validation occurs because the plugin accepts payment amounts directly from user-controlled POST data within the
create payment intent() and create subscription intent() functions without validating them against the configured price of the form. This allows unauthenticated attackers to modify the payment amount to an arbitrary value during Stripe payment form submission, potentially enabling the purchase of products or services at reduced prices.Recommendations
Update SureForms – Drag and Drop Form Builder for WordPress to version 2.2.2 or later.
As a temporary workaround, restrict access to the
create payment intent() and create subscription intent() functions.Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sureforms – Drag & Drop Contact Form & Form Builder
Sureforms