Sureforms
Vendor:
First CVE: Jan 8, 2025 · Active for 1 year
7
Total CVEs
More Total CVEs than 83% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 15% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Sureforms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 8, 2025
18 months ago
Most Recent CVE
Aug 1, 2025
357 days ago
CVE Severity & Scoring
Sureforms7 CVEs
29%
43%
29%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (71.4%)
High2 (28.6%)
Unknown0 (0.0%)
User Interaction
None2 (28.6%)
Unknown0 (0.0%)
Required5 (71.4%)
Privileges Required
Low0 (0.0%)
High3 (42.9%)
None4 (57.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-6691HIGH The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_ | Jul 9, 2025 | 8.1 | 25 | NO | NO |
CVE-2025-5921MEDIUM The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could | Aug 1, 2025 | 5.8 | 21 | NO | NO |
CVE-2025-6742HIGH The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.3 via the use of file_ | Jul 9, 2025 | 7.5 | 19 | NO | NO |
CVE-2024-12713MEDIUM The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the handle_expor | Jan 8, 2025 | 5.3 | 17 | NO | NO |
CVE-2025-3471MEDIUM The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to | Apr 30, 2025 | 4.9 | 16 | NO | NO |
The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Si | May 2, 2025 | 3.5 | 15 | NO | NO |
The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Si | May 2, 2025 | 3.5 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Sureforms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.5.0 | 2 | 7.8 | 0.7% | 0 | 0 |