Executive brief
Brainstorm Force SureForms is a form builder plugin for WordPress used by site owners to create contact forms and collect user data. This vulnerability allows an unauthenticated attacker to bypass access controls and view or manipulate form data belonging to other users by modifying identifiers in HTTP requests. An exploit could expose sensitive user information submitted through forms or allow unauthorized modifications to form submissions.
Technical details
This is an Insecure Direct Object Reference (IDOR) vulnerability in the SureForms WordPress plugin (versions up to 2.12.5) caused by inadequate access control verification when users access form objects. The plugin fails to properly validate that the requesting user has authorization to access form data identified by user-controlled IDs in URLs or API requests. An unauthenticated attacker can modify these identifiers to view or manipulate form submissions belonging to other users. The vulnerability is network-accessible and requires no authentication or user interaction. A patch was released in version 2.12.6.
Affected products
- Brainstorm Force SureForms through 2.12.5
Timeline
- 2026-09-03: disclosed
- 2026-09-03: patched: patch available in version 2.12.6