Junglewise Threat Intelligence

CVE-2026-11567: SureForms WordPress plugin payment amount bypass in dynamic forms

CVE-2026-11567 · Severity: info · CVSS 5.9 · Published 2026-07-14

Executive brief

SureForms, a WordPress plugin used to create payment and contact forms, contains a flaw that allows customers to bypass intended pricing. On forms where the price is set dynamically or hidden, an unauthenticated user can modify the payment amount to pay less than the required price for products or subscriptions. This could result in financial loss for businesses using the plugin to process transactions.

Technical details

A payment amount bypass vulnerability exists in SureForms versions prior to 2.11.1 due to insufficient server-side validation of payment amounts. When a form is configured to use a dynamically-sourced (variable or hidden) payment field, the plugin does not verify that the submitted amount matches the intended price. An unauthenticated remote attacker can manipulate the payment request to specify an arbitrary, lower price. This issue specifically affects dynamic pricing configurations; forms with fixed prices are not impacted. The vulnerability is addressed in version 2.11.1.

Affected products

  • SureForms SureForms before 2.11.1

Timeline

  • 2026-06-23: disclosed
  • 2026-06-23: advisory: WPScan advisory published
  • 2026-07-14: advisory: NVD advisory published

References