CVE Database /
CVE-2025-12535
CVE · Medium
CVE-2025-12535 — SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz [sureforms] < 1.13.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-12535
|
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz [sureforms] < 1.13.2 |
Cross-Site Request Forgery (CSRF) |
Medium
5.3
|
< 1.13.2
|
1.13.2 |
2025-11-18 |
—
|
CVE-2025-12535
The SureForms WordPress plugin has a security flaw in versions up to 1.13.1, which allows attackers to bypass protection against malicious requests from unknown sources. This is due to the plugin giving out generic security tokens to anyone who asks for them, rather than using special tokens tied to each form. As a result, an attacker can trick the system into performing unauthorized actions on certain endpoints without needing any extra permission checks.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings