SureForms WordPress Plugin Sensitive Information Disclosure Vulnerability
Vulnerability
A vulnerability allowing sensitive information disclosure exists in the SureForms – Drag and Drop Form Builder for WordPress plugin, affecting all versions prior to 1.12.1. The issue arises from inadequate access control on the '/wp-json/sureforms/v1/srfm-global-settings' REST API endpoint. This flaw enables authenticated attackers with contributor-level access and above to access sensitive data, including API keys for Google reCAPTCHA, Cloudflare Turnstile, hCaptcha, admin email addresses, and security-related form settings.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive information, such as API keys for various services and admin email addresses, potentially allowing for further attacks or exploitation.
Remediation
Users are advised to update the SureForms WordPress plugin to version 1.12.2 or later.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
