Payment Amount Bypass in SureForms Contact and Payment Form Plugin by WordPress
CVE-2026-4987
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 March 2026
What is CVE-2026-4987?
The SureForms plugin for WordPress, specifically in versions up to and including 2.5.2, contains a vulnerability that allows unauthenticated attackers to bypass payment amount validation. This issue arises from the create_payment_intent() function, which relies solely on a user-controlled parameter for payment validation. Attackers can exploit this flaw by setting the form_id to 0, enabling them to create underpriced payment and subscription intents, effectively undermining the intended payment processing mechanism of the plugin.
Affected Version(s)
SureForms β Contact Form, Payment Form & Other Custom Form Builder 0 <= 2.5.2