CVE-2025-3513: SureForms < 1.4.4 - Admin+ Stored XSS
The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3513?
CVE-2025-3513 has a high severity rating due to the potential for Stored Cross-Site Scripting attacks by privileged users.
How do I fix CVE-2025-3513?
To fix CVE-2025-3513, update the SureForms WordPress plugin to version 1.4.4 or later.
Who is affected by CVE-2025-3513?
Users of the SureForms WordPress plugin prior to version 1.4.4 are affected by CVE-2025-3513.
What type of attacks does CVE-2025-3513 enable?
CVE-2025-3513 enables Stored Cross-Site Scripting attacks, which can compromise user data through malicious scripts.
Can CVE-2025-3513 be exploited in a multisite environment?
Yes, CVE-2025-3513 can be exploited in a multisite WordPress environment even if the unfiltered_html capability is disallowed.