5.3
CVE-2025-12536
- EPSS 0.05%
- Veröffentlicht 13.11.2025 03:27:39
- Zuletzt bearbeitet 14.11.2025 16:42:03
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
SureForms <= 1.13.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure
The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.1 via the '_srfm_email_notification' post meta registration. This is due to setting the 'auth_callback' parameter to '__return_true', which allows unauthenticated access to the metadata. This makes it possible for unauthenticated attackers to extract sensitive data including email notification configurations, which frequently contain vendor-provided CRM/help desk dropbox addresses, CC/BCC recipients, and notification templates that can be abused to inject malicious data into downstream systems.
Mögliche Gegenmaßnahme
SureForms – Contact Form, Payment Form & Other Custom Form Builder: Update to version 1.13.2, or a newer patched version
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
SureForms – Contact Form, Payment Form & Other Custom Form Builder
Version
*-1.13.1
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerbrainstormforce
≫
Produkt
SureForms – Contact Form, Custom Form Builder, Calculator & More
Default Statusunaffected
Version <=
1.13.1
Version
*
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.168 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-359 Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.