ZeroHour

CVE-2025-8282

CVSS 3.1
3.5 low
EPSS
<1%p9
Published
()
Modified
Description

The SureForms WordPress plugin before 1.9.1 does not sanitise and escape some parameters when outputing them in the page, which could allow admin and above users to perform Cross-Site Scripting attacks.

Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.