CVE-2025-5921: SureForms < 1.7.2 - Reflected XSS
Published Aug 1, 2025
·Updated
The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both authenticated and unauthenticated users.
Affected Software
2 affected components
SureForms SureForms<1.7.2
Brainstormforce Sureforms Wordpress<1.7.2
Event History
Aug 1, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-5921?
The severity of CVE-2025-5921 is considered high due to the potential for reflected cross-site scripting attacks.
2
How do I fix CVE-2025-5921?
To fix CVE-2025-5921, update the SureForms WordPress plugin to version 1.7.2 or later.
3
What type of vulnerability is CVE-2025-5921?
CVE-2025-5921 is a reflected cross-site scripting (XSS) vulnerability.
4
Who is affected by CVE-2025-5921?
Both authenticated and unauthenticated users can be affected by CVE-2025-5921.
5
What software is affected by CVE-2025-5921?
CVE-2025-5921 affects the SureForms WordPress plugin versions prior to 1.7.2.