SureForms <= 1.13.1 - Sensitive Information Exposure
CVE-2025-12536
Verified
Description
SureForms WordPress plugin <= 1.13.1 contains a sensitive information exposure caused by setting 'auth_callback' to '__return_true' in '_srfm_email_notification' post meta registration, letting unauthenticated attackers access sensitive email notification data, exploit requires no authentication.
Severity
Medium
CVSS Score
5.3
Exploit Probability
1%
Affected Product
sureforms
Published Date
April 6, 2026
Template Author
pussycat0x
CVE-2025-12536.yaml
5.3Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE ID:
cve-2025-12536
CWE ID:
cwe-862
References
https://patchstack.com/database/wordpress/plugin/sureforms/vulnerability/wordpress-sureforms-plugin-1-13-1-unauthenticated-sensitive-information-exposure-vulnerabilityhttps://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sureforms/sureforms-1131-missing-authorization-to-unauthenticated-sensitive-information-exposure
Remediation Steps
Update to the latest version beyond 1.13.1.