Description
The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.1 via the '_srfm_email_notification' post meta registration. This is due to setting the 'auth_callback' parameter to '__return_true', which allows unauthenticated access to the metadata. This makes it possible for unauthenticated attackers to extract sensitive data including email notification configurations, which frequently contain vendor-provided CRM/help desk dropbox addresses, CC/BCC recipients, and notification templates that can be abused to inject malicious data into downstream systems.
Problem types
CWE-359 Exposure of Private Personal Information to an Unauthorized Actor
Product status
* (semver)
Timeline
| 2025-10-30: | Vendor Notified |
| 2025-11-12: | Disclosed |
Credits
M Indra Purnama
References
www.wordfence.com/...-0ddf-479e-b94b-7844ff6e9e81?source=cve
plugins.trac.wordpress.org/...tags/1.13.1/inc/post-types.php
plugins.trac.wordpress.org/...forms/trunk/inc/post-types.php