Junglewise Threat Intelligence

CVE-2026-7623: Brainstorm Force SureForms stored XSS in headingWrapper parameter

CVE-2026-7623 · Severity: medium · CVSS 6.4 · Published 2026-08-01

Executive brief

SureForms is a WordPress plugin used to create contact forms, payment forms, and surveys. A security vulnerability in this plugin allows users with basic contributor-level access to inject malicious scripts into website pages. If exploited, these scripts will run automatically whenever a visitor views the affected page, potentially leading to unauthorized actions or data theft.

Technical details

The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'headingWrapper' parameter within the Advanced Heading block. The vulnerability exists in all versions up to and including 2.8.1. An authenticated attacker with at least contributor-level permissions can inject arbitrary JavaScript into a page. This script executes in the context of any user (including administrators) who subsequently visits the compromised page. The issue was addressed in version 2.8.2 by improving sanitization within the Gutenberg block distribution files.

Affected products

  • Brainstorm Force SureForms – Contact Form, Payment Form & Other Custom Form Builder up to, and including, 2.8.1

Timeline

  • 2026-07-31: disclosed: Vulnerability reported by Wordfence
  • 2026-07-31: patched: Version 2.8.2 released to address the issue
  • 2026-08-01: advisory: NVD publication date

References

Related threats