
Cloud Vulnerability DB
A community-led vulnerabilities database
The SureForms plugin for WordPress contains a Sensitive Information Exposure vulnerability (CVE-2025-12536) affecting all versions up to and including 1.13.1. The vulnerability was disclosed on November 13, 2025 and stems from improper authorization settings in the 'srfmemail_notification' post meta registration (AttackerKB).
The vulnerability exists due to setting the 'authcallback' parameter to '_return_true' in the post meta registration, which effectively bypasses authentication checks. This misconfiguration allows unauthenticated users to access email notification metadata that should be restricted (AttackerKB).
Attackers can extract sensitive data including email notification configurations, vendor-provided CRM/help desk dropbox addresses, CC/BCC recipients, and notification templates. This exposed information could be leveraged to inject malicious data into downstream systems or conduct further targeted attacks (AttackerKB).
Users should update to a version newer than 1.13.1 once available. Until then, website administrators should monitor for unauthorized access attempts to the email notification configurations and consider implementing additional access controls at the web application firewall level (AttackerKB).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."