SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-11567

MEDIUM · CVSS 5.9 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

The SureForms WordPress plugin prior to version 2.11.1 is vulnerable due to inadequate validation of dynamically-sourced payment amounts, enabling unauthenticated users to submit underpayments for products or subscriptions. This flaw could lead to revenue loss for businesses relying on the plugin for transactions. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential financial impacts.

CVE
CVE-2026-11567
Severity
MEDIUM
CVSS
5.9
EPSS
0.18%
WordPress

Original NVD Description

The SureForms WordPress plugin before 2.11.1 does not properly validate the payment amount on forms that use a dynamically-sourced (variable/hidden) payment amount, allowing unauthenticated users to underpay for the configured product or subscription. Forms using a fixed configured price are not affected.