CVE-2025-3471
CVSS 3.1 Score 4.9 of 10 (medium)
Details
Published Apr 30, 2025
Updated: May 9, 2025
Summary
CVE-2025-3471: This vulnerability affects the SureForms WordPress plugin before version 1.4.4. It involves inadequate authorization checks when updating plugin settings via the REST API. Contributor and above roles can exploit this issue, making it essential for users to update to the latest plugin version to mitigate the risk of unauthorized plugin configuration changes.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Brainstorm Force