SureForms <= 2.11.0 - Unauthenticated Payment Amount Bypass
2026-06-23 00:00
Yaswanth Reddy SunkaraStrategic Overview
StatusPatched in 2.11.1
Affected Version
<= 2.11.0CVSS5.3Medium
CVE
CVE-2026-11567Vulnerability Overview
The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Payment Amount Bypass in all versions up to, and including, 2.11.0. This makes it possible for unauthenticated attackers to pay less than is intended.
Technical Analysis
REMEDIATION: Update to version 2.11.1, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C