Vulnerability Description
The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both authenticated and unauthenticated users.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Brainstormforce | Sureforms | < 1.7.2 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/052fb6cf-274e-468b-a7e0-0e7a1751ec75/Third Party Advisory
FAQ
What is CVE-2025-5921?
CVE-2025-5921 is a vulnerability with a CVSS score of 5.8 (MEDIUM). The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against bot...
How severe is CVE-2025-5921?
CVE-2025-5921 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-5921?
Check the references section above for vendor advisories and patch information. Affected products include: Brainstormforce Sureforms.