We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to perform such action
Reserved 2025-04-09 | Published 2025-04-30 | Updated 2025-04-30 | Assigner WPScanCWE-863 Incorrect Authorization
Dmitrii Ignatyev
WPScan
wpscan.com/...rability/aa21dd2b-1277-4cf9-b7f6-d4f8a6d518c1/
Support options