Payment Amount Bypass in SureForms Contact and Payment Form Plugin by WordPress
CVE-2026-4987
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 March 2026
What is CVE-2026-4987?
The SureForms plugin for WordPress, specifically in versions up to and including 2.5.2, contains a vulnerability that allows unauthenticated attackers to bypass payment amount validation. This issue arises from the create_payment_intent() function, which relies solely on a user-controlled parameter for payment validation. Attackers can exploit this flaw by setting the form_id to 0, enabling them to create underpriced payment and subscription intents, effectively undermining the intended payment processing mechanism of the plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SureForms β Contact Form, Payment Form & Other Custom Form Builder * <= 2.5.2