PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-11567 SureForms CVE debrief

The SureForms WordPress plugin before 2.11.1 has a vulnerability allowing unauthenticated users to underpay for configured products or subscriptions due to improper validation of dynamically-sourced payment amounts. This vulnerability affects forms using dynamically-sourced payment amounts, while forms with fixed configured prices are not affected. The vulnerability has a medium defensive priority, and users of the plugin, especially those using forms with dynamically-sourced payment amounts, should be aware of this vulnerability and take steps to mitigate it. Mitigation steps include updating the plugin to version 2.11.1 or later, reviewing and adjusting forms using dynamically-sourced payment amounts, and monitoring for suspicious activity related to payment processing.

Vendor
SureForms
Product
SureForms WordPress plugin
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-14
Original CVE updated
2026-07-14
Advisory published
2026-07-14
Advisory updated
2026-07-14

Who should care

Users of the SureForms WordPress plugin, especially those using forms with dynamically-sourced payment amounts, should be aware of this vulnerability and take steps to mitigate it. This includes administrators of WordPress sites using the SureForms plugin, security teams responsible for monitoring and responding to vulnerabilities, and operators of e-commerce sites that use the plugin for payment processing.

Technical summary

The SureForms WordPress plugin before 2.11.1 does not properly validate payment amounts on forms that use a dynamically-sourced (variable/hidden) payment amount. This allows unauthenticated users to underpay for the configured product or subscription. Forms using a fixed configured price are not affected. The vulnerability has a medium defensive priority, and defenders should review the plugin version, payment form configurations, and monitor for suspicious activity related to payment processing.

Defensive priority

Medium

Recommended defensive actions

  • Update the SureForms WordPress plugin to version 2.11.1 or later
  • Review and adjust forms using dynamically-sourced payment amounts
  • Monitor for suspicious activity related to payment processing
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The SureForms WordPress plugin before 2.11.1 has a vulnerability allowing unauthenticated users to underpay for configured products or subscriptions due to improper validation of dynamically-sourced payment amounts. Evidence is limited; verification of vulnerability details and affected versions is recommended. Defenders should verify the plugin version, review payment form configurations, and monitor for suspicious activity related to payment processing. Additional verification tasks include checking for updates to the plugin and reviewing security advisories from the vendor.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-11567 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-11567

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-11567 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-11567

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.