CVE · Medium

CVE-2024-12713 — SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz [sureforms] < 1.2.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-12713 SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz [sureforms] < 1.2.3 Missing Authorization Medium 5.3 < 1.2.3 1.2.3 2025-01-07

CVE-2024-12713

The SureForms plugin versions 1.2.2 and earlier contain an information exposure vulnerability in the handle_export_form() function that lacks proper authorization verification. Unauthenticated users can exploit this flaw to export sensitive data from restricted posts, including those marked as password protected, private, or draft status. The vulnerability allows unauthorized access to information that should remain inaccessible to such users. The issue was resolved in version 1.2.3.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.