S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Apr 7, 2026

CVE-2025-14437 Scanner

CVE-2025-14437 Scanner - Information Disclosure vulnerability in SureForms

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.8k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-12536
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.1 via the '_srfm_email_notification' post meta registration. This is due to setting the 'auth_callback' parameter to '__return_true', which allows unauthenticated access to the metadata. This makes it possible for unauthenticated attackers to extract sensitive data including email notification configurations, which frequently contain vendor-provided CRM/help desk dropbox addresses, CC/BCC recipients, and notification templates that can be abused to inject malicious data into downstream systems.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
SureForms – Contact Form, Payment Form & Other Custom Form Builderby brainstormforce
0
Updated Aug 22, 2026View on NVD →
Detail

SureForms is a popular WordPress plugin used to create custom forms for websites. It's widely employed by web developers and site owners to facilitate user interaction and data collection. The plugin is essential for businesses and individuals seeking to streamline customer feedback, surveys, or contact requests. As it integrates directly into WordPress, it benefits from the platform's widespread adoption and ease of use. The plugin's user-friendly interface and robust features have made it a preferred choice for thousands of WordPress websites. Consequently, maintaining its security is crucial to safeguarding user data and ensuring seamless web operations.

The vulnerability allows unauthenticated attackers to access sensitive information due to improper authorization settings. Specifically, it involves the exposure of email notification configurations. Such vulnerabilities can lead to unauthorized access to critical data, potentially resulting in data leakage. The flaw lies in setting the 'auth_callback' to '__return_true', which inadequately protects sensitive data. This vulnerability requires immediate attention due to its potential impact on data integrity and privacy. Users of the affected plugin versions are advised to update to mitigate these risks.

Technical details reveal that the vulnerability is present due to a lack of authorization checks in certain endpoints. The exposure is due to setting 'auth_callback' to '__return_true' for the '_srfm_email_notification' post meta registration. This setup allows unauthenticated access to sensitive data fields. Key endpoints include '/wp-json/wp/v2/sureforms_form', which return sensitive email information. Ineffectively protected endpoints pose a significant risk of exploitation. Therefore, updating to a secure version is recommended to prevent unauthorized data exposure.

Exploitation of this vulnerability can result in significant data leaks. Unauthorized individuals can access email configurations, leading to privacy breaches. Leaks may result in the abuse of email data for spam or phishing attacks. These breaches undermine trust and could lead to reputational damage for affected websites. Furthermore, exposed sensitive data can be exploited in broader cyber-attacks. Addressing the vulnerability promptly is essential to maintaining data security and user trust.

REFERENCES

Solution Advice
  • Immediately update SureForms to a version later than 1.13.1.
  • Restrict access to critical configuration files in WordPress plugins.
  • Implement strict authorization protocols for sensitive data access.
  • Regularly audit plugins for security vulnerabilities and apply updates promptly.
  • Use security plugins to monitor and restrict unauthorized access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.