CVE · High

CVE-2026-15288 — SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz [sureforms] < 2.2.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15288 SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz [sureforms] < 2.2.2 Improper Input Validation High 7.5 < 2.2.2 2.2.2 2026-02-13

CVE-2026-15288

The SureForms plugin, used with WordPress, contains an issue in its handling of user-submitted data. Specifically, versions 2.2.1 and earlier allow attackers to manipulate the payment amount by exploiting a lack of input validation in certain functions. This vulnerability makes it possible for unauthorized users to alter payment prices during Stripe transactions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.