Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 18 vulnerability records associated with SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz, published between 2025 and 2026.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

At a glance

Security Snapshot

18Total records
0Critical
5High
13Medium
0Low
0Informational
18Patched records
0Currently marked unpatched
2025-01-07First disclosure
2026-07-31Latest disclosure
17 of 18CVE coverage

Use this history

Check and watch SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz.

A history record does not establish whether the version installed on your website is affected. Enter the exact version in the checker, or add this software to a private Critical/High alert watchlist.

Year-by-Year Timeline

YearRecordsRelative volume
20251313 records
202655 records

Severity Breakdown

SeverityRecordsShare
High527.8%
Medium1372.2%

Vulnerability-Type Breakdown

Cross-Site Scripting

6 records33.3%

First: 2025. Latest: 2026.

Missing Authorization

5 records27.8%

First: 2025. Latest: 2026.

Other

3 records16.7%

First: 2025. Latest: 2026.

Path Traversal

1 record5.6%

First: 2025. Latest: 2025.

Information Disclosure

1 record5.6%

First: 2025. Latest: 2025.

CSRF

1 record5.6%

First: 2025. Latest: 2025.

Privilege Escalation

1 record5.6%

First: 2026. Latest: 2026.

Patch Status

Patched
18
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 2.8.2
  • 2.11.1
  • 2.6.0
  • 2.2.2
  • 2.2.1
  • 1.13.2
  • 1.12.2
  • 1.12.1
  • 1.9.1
  • 1.7.2
  • 1.7.4
  • 1.6.5
  • 1.5.1
  • 1.4.5
  • 1.3.2
  • 1.2.5
  • 1.1.2
  • 1.0.7
  • 0.0.14
  • 1.4.4
  • 1.2.3

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-2.8.1SureForms <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'headingWrapper' Block AttributeJuly 31, 20262.8.2Medium
*-2.11.0SureForms <= 2.11.0 - Unauthenticated Payment Amount BypassJune 23, 20262.11.1Medium
*-2.5.2SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id'March 27, 20262.6.0High
*-2.2.1SureForms <= 2.2.1 - Missing AuthorizationFebruary 15, 20262.2.2Medium
*-2.2.1SureForms – Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticated Stripe Payment Amount ManipulationFebruary 13, 20262.2.2High
*-2.2.0SureForms <= 2.2.0 - Unauthenticated Stored Cross-Site ScriptingDecember 20, 20252.2.1High
*-1.13.1SureForms <= 1.13.1 - Cross-Site Request Forgery Protection Bypass via Improper Nonce DistributionNovember 18, 20251.13.2Medium
*-1.13.1SureForms <= 1.13.1 - Missing Authorization to Unauthenticated Sensitive Information ExposureNovember 12, 20251.13.2Medium
*-1.12.1SureForms – Drag and Drop Form Builder for WordPress <= 1.12.1 - Missing Authorization to Authenticated (Contributor+) Information DisclosureOctober 13, 20251.12.2Medium
*-1.12.0SureForms – Drag and Drop Form Builder for WordPress <= 1.12.0 - Missing Authorization to Authenticated (Contributor+) Form CreationSeptember 19, 20251.12.1Medium
*-1.9.0SureForms – Drag and Drop Form Builder for WordPress <= 1.9.0 - Authenticated (Admin+) Stored Cross-Site ScriptingSeptember 2, 20251.9.1Medium
*-1.7.1SureForms <= 1.7.1 - Reflected Cross-Site ScriptingJuly 11, 20251.7.2Medium
1.7-1.7.3SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission DeletionJuly 8, 20250.0.14, 1.0.7, 1.1.2, 1.2.5, 1.3.2, 1.4.5, 1.5.1, 1.6.5, 1.7.4High
1.6-1.6.4SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission DeletionJuly 8, 20250.0.14, 1.0.7, 1.1.2, 1.2.5, 1.3.2, 1.4.5, 1.5.1, 1.6.5, 1.7.4High
1.5SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission DeletionJuly 8, 20250.0.14, 1.0.7, 1.1.2, 1.2.5, 1.3.2, 1.4.5, 1.5.1, 1.6.5, 1.7.4High
1.4-1.4.4SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission DeletionJuly 8, 20250.0.14, 1.0.7, 1.1.2, 1.2.5, 1.3.2, 1.4.5, 1.5.1, 1.6.5, 1.7.4High
1.3-1.3.1SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission DeletionJuly 8, 20250.0.14, 1.0.7, 1.1.2, 1.2.5, 1.3.2, 1.4.5, 1.5.1, 1.6.5, 1.7.4High
1.2-1.2.4SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission DeletionJuly 8, 20250.0.14, 1.0.7, 1.1.2, 1.2.5, 1.3.2, 1.4.5, 1.5.1, 1.6.5, 1.7.4High
1.1-1.1.1SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission DeletionJuly 8, 20250.0.14, 1.0.7, 1.1.2, 1.2.5, 1.3.2, 1.4.5, 1.5.1, 1.6.5, 1.7.4High
1.0-1.0.6SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission DeletionJuly 8, 20250.0.14, 1.0.7, 1.1.2, 1.2.5, 1.3.2, 1.4.5, 1.5.1, 1.6.5, 1.7.4High
0.0-0.0.13SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission DeletionJuly 8, 20250.0.14, 1.0.7, 1.1.2, 1.2.5, 1.3.2, 1.4.5, 1.5.1, 1.6.5, 1.7.4High
1.7-1.7.3SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated PHP Object Injection (PHAR) Triggered via Admin Submission DeletionJuly 8, 20250.0.14, 1.0.7, 1.1.2, 1.2.5, 1.3.2, 1.4.5, 1.5.1, 1.6.5, 1.7.4High
1.6-1.6.4SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated PHP Object Injection (PHAR) Triggered via Admin Submission DeletionJuly 8, 20250.0.14, 1.0.7, 1.1.2, 1.2.5, 1.3.2, 1.4.5, 1.5.1, 1.6.5, 1.7.4High
1.5SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated PHP Object Injection (PHAR) Triggered via Admin Submission DeletionJuly 8, 20250.0.14, 1.0.7, 1.1.2, 1.2.5, 1.3.2, 1.4.5, 1.5.1, 1.6.5, 1.7.4High
1.4-1.4.4SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated PHP Object Injection (PHAR) Triggered via Admin Submission DeletionJuly 8, 20250.0.14, 1.0.7, 1.1.2, 1.2.5, 1.3.2, 1.4.5, 1.5.1, 1.6.5, 1.7.4High

Selected source records

Latest Records

MediumCVE-2026-7623

SureForms <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'headingWrapper' Block Attribute

Published: July 31, 2026

Affected versions
*-2.8.1
Patched versions
2.8.2
Original Wordfence record
MediumCVE-2026-11567

SureForms <= 2.11.0 - Unauthenticated Payment Amount Bypass

Published: June 23, 2026

Affected versions
*-2.11.0
Patched versions
2.11.1
Original Wordfence record
HighCVE-2026-4987

SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id'

Published: March 27, 2026

Affected versions
*-2.5.2
Patched versions
2.6.0
Original Wordfence record
Medium

SureForms <= 2.2.1 - Missing Authorization

Published: February 15, 2026

Affected versions
*-2.2.1
Patched versions
2.2.2
Original Wordfence record
HighCVE-2026-15288

SureForms – Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticated Stripe Payment Amount Manipulation

Published: February 13, 2026

Affected versions
*-2.2.1
Patched versions
2.2.2
Original Wordfence record
HighCVE-2025-14855

SureForms <= 2.2.0 - Unauthenticated Stored Cross-Site Scripting

Published: December 20, 2025

Affected versions
*-2.2.0
Patched versions
2.2.1
Original Wordfence record
MediumCVE-2025-12535

SureForms <= 1.13.1 - Cross-Site Request Forgery Protection Bypass via Improper Nonce Distribution

Published: November 18, 2025

Affected versions
*-1.13.1
Patched versions
1.13.2
Original Wordfence record
MediumCVE-2025-12536

SureForms <= 1.13.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure

Published: November 12, 2025

Affected versions
*-1.13.1
Patched versions
1.13.2
Original Wordfence record

Highest-Severity Records

HighCVE-2025-6691

SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission Deletion

Published: July 8, 2025

Affected versions
0.0-0.0.13; 1.0-1.0.6; 1.1-1.1.1; 1.2-1.2.4; 1.3-1.3.1; 1.4-1.4.4; 1.5; 1.6-1.6.4; 1.7-1.7.3
Patched versions
0.0.14, 1.0.7, 1.1.2, 1.2.5, 1.3.2, 1.4.5, 1.5.1, 1.6.5, 1.7.4
Original Wordfence record
HighCVE-2025-6742

SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated PHP Object Injection (PHAR) Triggered via Admin Submission Deletion

Published: July 8, 2025

Affected versions
0.0-0.0.13; 1.0-1.0.6; 1.1-1.1.1; 1.2-1.2.4; 1.3-1.3.1; 1.4-1.4.4; 1.5; 1.6-1.6.4; 1.7-1.7.3
Patched versions
0.0.14, 1.0.7, 1.1.2, 1.2.5, 1.3.2, 1.4.5, 1.5.1, 1.6.5, 1.7.4
Original Wordfence record
HighCVE-2026-15288

SureForms – Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticated Stripe Payment Amount Manipulation

Published: February 13, 2026

Affected versions
*-2.2.1
Patched versions
2.2.2
Original Wordfence record
HighCVE-2026-4987

SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id'

Published: March 27, 2026

Affected versions
*-2.5.2
Patched versions
2.6.0
Original Wordfence record
HighCVE-2025-14855

SureForms <= 2.2.0 - Unauthenticated Stored Cross-Site Scripting

Published: December 20, 2025

Affected versions
*-2.2.0
Patched versions
2.2.1
Original Wordfence record
MediumCVE-2026-7623

SureForms <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'headingWrapper' Block Attribute

Published: July 31, 2026

Affected versions
*-2.8.1
Patched versions
2.8.2
Original Wordfence record
MediumCVE-2025-5921

SureForms <= 1.7.1 - Reflected Cross-Site Scripting

Published: July 11, 2025

Affected versions
*-1.7.1
Patched versions
1.7.2
Original Wordfence record
Medium

SureForms <= 2.2.1 - Missing Authorization

Published: February 15, 2026

Affected versions
*-2.2.1
Patched versions
2.2.2
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory