The SureForms  WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to perform such action
                
            References
                    | Link | Resource | 
|---|---|
| https://wpscan.com/vulnerability/aa21dd2b-1277-4cf9-b7f6-d4f8a6d518c1/ | Third Party Advisory Exploit | 
Configurations
                    History
                    09 May 2025, 13:48
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://wpscan.com/vulnerability/aa21dd2b-1277-4cf9-b7f6-d4f8a6d518c1/ - Third Party Advisory, Exploit | |
| CPE | cpe:2.3:a:brainstormforce:sureforms:*:*:*:*:*:wordpress:*:* | |
| First Time | Brainstormforce Brainstormforce sureforms | |
| CWE | NVD-CWE-noinfo | 
30 Apr 2025, 18:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 4.9 | 
| Summary | 
 | 
30 Apr 2025, 06:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-04-30 06:15
Updated : 2025-05-09 13:48
NVD link : CVE-2025-3471
Mitre link : CVE-2025-3471
CVE.ORG link : CVE-2025-3471
JSON object : View
Products Affected
                brainstormforce
- sureforms
CWE
                