Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23340 | The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both authenticated and unauthenticated users. |
Wed, 06 Aug 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:brainstormforce:sureforms:*:*:*:*:*:wordpress:*:* |
Mon, 04 Aug 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brainstormforce
Brainstormforce sureforms Wordpress Wordpress wordpress |
|
| Vendors & Products |
Brainstormforce
Brainstormforce sureforms Wordpress Wordpress wordpress |
Fri, 01 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 01 Aug 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both authenticated and unauthenticated users. | |
| Title | SureForms < 1.7.2 - Reflected XSS | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-08-01T13:39:38.917Z
Reserved: 2025-06-09T13:48:38.281Z
Link: CVE-2025-5921
Updated: 2025-08-01T13:39:18.878Z
Status : Analyzed
Published: 2025-08-01T06:15:29.127
Modified: 2025-08-06T16:48:59.193
Link: CVE-2025-5921
No data.
OpenCVE Enrichment
Updated: 2025-08-04T09:00:46Z
EUVD