← back
CVE-2025-3471medium

SureForms < 1.4.4 - Contributor+ Settings Update

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.9epss 0.4%
exploitation probability
0.4%top 73% of all CVEs
observed exploitation
nono source reports it
The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to perform such action
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Affected products
Unknown · SureForms