SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via form_id
CVE-2026-4987
Verified
Description
The SureForms plugin for WordPress is vulnerable to payment amount validation bypass in versions up to, and including, 2.5.2. The create_payment_intent AJAX handler checks `if ($form_id > 0 && !empty($block_id))` before calling validate_payment_amount(). By sending form_id=0 (the default intval of a missing/zero value), an unauthenticated attacker completely skips the server-side amount validation and can create Stripe payment intents with arbitrary amounts, bypassing configured pricing.
Severity
High
CVSS Score
7.5
Exploit Probability
1%
Affected Product
sureforms
Published Date
July 23, 2026
Template Author
iamatownboy
CVE-2026-4987.yaml
7.5Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVE ID:
cve-2026-4987
CWE ID:
cwe-20
Remediation Steps
Update SureForms to version 2.6.0 or later.