CVE-2026-42377: WordPress SureForms Pro plugin <= 2.8.0 - Broken Access Control vulnerability
Published Apr 29, 2026
·Updated
Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects SureForms Pro: from n/a through 2.8.0.
Affected Software
1 affected component
Brainstorm Force SureForms Pro<=2.8.0
Remediation
Information
Update the WordPress SureForms Pro Plugin to the latest available version (at least 2.8.1).
Event History
Apr 29, 2026
CVE Published
via MITRE·07:27 AM
Data Sourced
via MITRE·07:27 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-42377?
CVE-2026-42377 is classified as a moderate severity vulnerability due to broken access controls.
2
How do I fix CVE-2026-42377?
To fix CVE-2026-42377, update the SureForms Pro plugin to a version higher than 2.8.0.
3
What impact does CVE-2026-42377 have on my WordPress site?
CVE-2026-42377 allows unauthorized users to exploit incorrectly configured access control security levels, potentially compromising site security.
4
Which versions of SureForms Pro are affected by CVE-2026-42377?
CVE-2026-42377 affects SureForms Pro versions from n/a through 2.8.0.
5
Is there a known exploit for CVE-2026-42377?
Yes, CVE-2026-42377 has known exploits that leverage the broken access control within the affected plugin.