CVE-2026-85308: WordPress SureForms plugin <= 2.12.5 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects SureForms: from n/a through 2.12.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress SureForms pluginto a version that resolves this vulnerability.Fixed in 2.12.6
Event History
Frequently Asked Questions
Does exploitation require an authenticated WordPress account or user interaction?
No. The listed vector indicates network-based exploitation with no privileges required and no user interaction required.
What is the expected security impact?
The supplied CVSS vector indicates low confidentiality impact. It indicates no integrity or availability impact, and the impact remains within the vulnerable security authority.
Which SureForms versions should be considered affected?
The issue is listed as affecting SureForms through version 2.12.5. The lower bound is unspecified, so installations running 2.12.5 or an earlier version should be reviewed.