/Vulnerability Library

SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via form_id

CVE-2026-4987
Verified

Description

The SureForms plugin for WordPress is vulnerable to payment amount validation bypass in versions up to, and including, 2.5.2. The create_payment_intent AJAX handler checks `if ($form_id > 0 && !empty($block_id))` before calling validate_payment_amount(). By sending form_id=0 (the default intval of a missing/zero value), an unauthenticated attacker completely skips the server-side amount validation and can create Stripe payment intents with arbitrary amounts, bypassing configured pricing.

Severity

High

CVSS Score

7.5

Exploit Probability

1%

Affected Product

sureforms

Published Date

July 23, 2026

Template Author

iamatownboy

CVE-2026-4987.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVE ID:
cve-2026-4987
CWE ID:
cwe-20

References

https://nvd.nist.gov/vuln/detail/CVE-2026-4987https://www.wordfence.com/threat-intel/vulnerabilities/id/c4772b32-a730-44f2-b43c-f9bd5abb6541?source=cvehttps://plugins.trac.wordpress.org/changeset/3488858/sureforms

Remediation Steps

Update SureForms to version 2.6.0 or later.