CVE-2025-10489: SureForms – Drag and Drop Form Builder for WordPress <= 1.12.0 - Missing Authorization to Authenticated (Contributor+) Form Creation
The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to unauthorized creation of forms due to a missing capability check on the registerposttypes() function in all versions up to, and including, 1.12.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to create forms when the user interface specifically prohibits it.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10489?
CVE-2025-10489 has a medium severity level due to the potential for unauthorized form creation.
How do I fix CVE-2025-10489?
To fix CVE-2025-10489, update the SureForms Drag and Drop Contact Form Builder plugin to the latest version beyond 1.12.
What versions are affected by CVE-2025-10489?
CVE-2025-10489 affects all versions of the SureForms Drag and Drop Contact Form Builder up to and including version 1.12.
What type of vulnerability is CVE-2025-10489?
CVE-2025-10489 is a vulnerability related to unauthorized access due to a missing capability check in the plugin.
Who is impacted by CVE-2025-10489?
Users of the SureForms Drag and Drop Contact Form Builder plugin for WordPress are impacted by CVE-2025-10489.