SureForms WordPress Plugin Sensitive Information Disclosure Vulnerability

Vulnerability

A vulnerability allowing sensitive information disclosure exists in the SureForms – Drag and Drop Form Builder for WordPress plugin, affecting all versions prior to 1.12.1. The issue arises from inadequate access control on the '/wp-json/sureforms/v1/srfm-global-settings' REST API endpoint. This flaw enables authenticated attackers with contributor-level access and above to access sensitive data, including API keys for Google reCAPTCHA, Cloudflare Turnstile, hCaptcha, admin email addresses, and security-related form settings.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information, such as API keys for various services and admin email addresses, potentially allowing for further attacks or exploitation.

Remediation

Users are advised to update the SureForms WordPress plugin to version 1.12.2 or later.

Added: Oct 14, 2025, 6:19 AM
Updated: Oct 14, 2025, 6:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.9
remediation
7.7
relevance
0.7
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.