SureForms WordPress Plugin Payment Amount Validation Bypass Vulnerability
Vulnerability
A vulnerability exists in the SureForms WordPress plugin, specifically in the Contact Form, Payment Form, and Custom Form Builder versions up to and including 2.5.2. The issue arises from the create_payment_intent() function, which validates payment amounts based solely on a user-controlled parameter. This flaw allows unauthenticated attackers to bypass payment validation and create underpriced payment or subscription intents by setting the form_id parameter to 0.
Impact
Exploitation of this vulnerability allows for unauthorized manipulation of payment amounts, potentially leading to financial loss or abuse of subscription services.
Remediation
Users are advised to update the SureForms WordPress plugin to version 2.6.0 or later, where this vulnerability has been patched.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
