SureForms
- <= 2.2.1
A vulnerability exists in the SureForms – Drag and Drop Form Builder for WordPress plugin, affecting all versions up to and including 2.2.1. The issue arises from improper input validation, as the plugin allows payment amounts to be submitted via user-controlled POST data in the 'create_payment_intent' and 'create_subscription_intent' functions, without verifying it against the form's set price. This flaw enables unauthenticated attackers to alter the payment amount to any desired value when using a Stripe payment form, potentially leading to the purchase of products or services at greatly reduced prices.
Exploitation of this vulnerability could result in unauthorized manipulation of payment amounts in Stripe transactions, allowing attackers to purchase items or services at significantly discounted rates.
Users are advised to update the SureForms WordPress plugin to version 2.2.2 or a later patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.