CVE Database /
CVE-2026-11567
CVE
CVE-2026-11567 — SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz [sureforms] < 2.11.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-11567
|
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz [sureforms] < 2.11.1 |
Improper Access Control |
Unknown
|
< 2.11.1
|
2.11.1 |
2026-06-23 |
—
|
CVE-2026-11567
The SureForms WordPress plugin has a security flaw in versions prior to 2.11.1, which allows unauthorized individuals to pay less than the set price for products or subscriptions when forms use a variable payment amount. This vulnerability occurs because the plugin doesn't adequately verify the payment amounts on these forms. As a result, users can exploit this weakness by submitting incorrect payments.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings