SureForms WordPress Plugin Payment Amount Validation Bypass Vulnerability

Vulnerability

A vulnerability exists in the SureForms WordPress plugin, specifically in the Contact Form, Payment Form, and Custom Form Builder versions up to and including 2.5.2. The issue arises from the create_payment_intent() function, which validates payment amounts based solely on a user-controlled parameter. This flaw allows unauthenticated attackers to bypass payment validation and create underpriced payment or subscription intents by setting the form_id parameter to 0.

Impact

Exploitation of this vulnerability allows for unauthorized manipulation of payment amounts, potentially leading to financial loss or abuse of subscription services.

Remediation

Users are advised to update the SureForms WordPress plugin to version 2.6.0 or later, where this vulnerability has been patched.

Added: Mar 28, 2026, 2:18 AM
Updated: Mar 28, 2026, 2:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.1
remediation
0.0
relevance
4.8
threat
3.2
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.