Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 30 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 30 Mar 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brainstormforce
Brainstormforce sureforms – Contact Form, Payment Form & Other Custom Form Builder Wordpress Wordpress wordpress |
|
| Vendors & Products |
Brainstormforce
Brainstormforce sureforms – Contact Form, Payment Form & Other Custom Form Builder Wordpress Wordpress wordpress |
Sat, 28 Mar 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amount Bypass in all versions up to, and including, 2.5.2. This is due to the create_payment_intent() function performing a payment validation solely based on the value of a user-controlled parameter. This makes it possible for unauthenticated attackers to bypass configured form payment-amount validation and create underpriced payment/subscription intents by setting form_id to 0. | |
| Title | SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id' | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:20:42.042Z
Reserved: 2026-03-27T12:55:03.320Z
Link: CVE-2026-4987
Updated: 2026-03-30T14:58:22.296Z
Status : Deferred
Published: 2026-03-28T02:16:14.793
Modified: 2026-04-24T16:36:24.067
Link: CVE-2026-4987
No data.
OpenCVE Enrichment
Updated: 2026-03-30T07:59:11Z