/Vulnerability Library

SureForms <= 1.13.1 - Sensitive Information Exposure

CVE-2025-12536
Verified

Description

SureForms WordPress plugin <= 1.13.1 contains a sensitive information exposure caused by setting 'auth_callback' to '__return_true' in '_srfm_email_notification' post meta registration, letting unauthenticated attackers access sensitive email notification data, exploit requires no authentication.

Severity

Medium

CVSS Score

5.3

Exploit Probability

1%

Affected Product

sureforms

Published Date

April 6, 2026

Template Author

pussycat0x

CVE-2025-12536.yaml
5.3Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE ID:
cve-2025-12536
CWE ID:
cwe-862

References

https://patchstack.com/database/wordpress/plugin/sureforms/vulnerability/wordpress-sureforms-plugin-1-13-1-unauthenticated-sensitive-information-exposure-vulnerabilityhttps://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sureforms/sureforms-1131-missing-authorization-to-unauthenticated-sensitive-information-exposure

Remediation Steps

Update to the latest version beyond 1.13.1.