SureForms WordPress Plugin Improper Input Validation Vulnerability Allowing Unauthenticated Stripe Payment Amount Manipulation

Vulnerability

A vulnerability exists in the SureForms – Drag and Drop Form Builder for WordPress plugin, affecting all versions up to and including 2.2.1. The issue arises from improper input validation, as the plugin allows payment amounts to be submitted via user-controlled POST data in the 'create_payment_intent' and 'create_subscription_intent' functions, without verifying it against the form's set price. This flaw enables unauthenticated attackers to alter the payment amount to any desired value when using a Stripe payment form, potentially leading to the purchase of products or services at greatly reduced prices.

Impact

Exploitation of this vulnerability could result in unauthorized manipulation of payment amounts in Stripe transactions, allowing attackers to purchase items or services at significantly discounted rates.

Remediation

Users are advised to update the SureForms WordPress plugin to version 2.2.2 or a later patched version.

Added: Jul 10, 2026, 5:44 AM
Updated: Jul 10, 2026, 5:44 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.1
remediation
0.0
relevance
9.4
threat
3.2
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.