Stored Cross-Site Scripting in SureForms Contact Form Plugin for WordPress
CVE-2026-7623

6.4MEDIUM

What is CVE-2026-7623?

The SureForms plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability through the 'headingWrapper' parameter. This issue arises due to inadequate input sanitization and output escaping, enabling authenticated users with contributor-level access or higher to insert malicious scripts. These scripts can execute when a user accesses the affected page, potentially compromising user data and overall site integrity. It is crucial for users of SureForms to update to the latest version to mitigate this risk.

Affected Version(s)

SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz 0 <= 2.8.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dmitrii Ignatyev
.