CVE-2026-4987Disclosure

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amount Bypass in all versions up to, and including, 2.5.2. This is due to the create_payment_intent() function performing a payment validation solely based on the value of a user-controlled parameter. This makes it possible for unauthenticated attackers to bypass configured form payment-amount validation and create underpriced payment/subscription intents by setting form_id to 0.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 7 classified signals
  • Peaked 2d ago at 5 mentions (2026-03-28); latest day: 1
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-03-28: 5Mentions · 2026-03-29: 1Mentions · 2026-07-29: 1PoC Mentioned / Linked · 2026-07-29: 1Technical Details · 2026-03-28: 4Technical Details · 2026-03-29: 1Technical Details · 2026-07-29: 103-2803-2907-29
Signal classification1 categories
Disclosure
7100.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-285
Disclosure5
2026-03-291
Disclosure1
2026-07-291
Disclosure1
Full discourse7 posts
  • EdgeDetectOps@EdgeDetectOps
    Disclosure

    WordPress payment forms accepting user-controlled amounts. No server validation. CVE-2026-4987 affects all SureForms versions up to 2.5.2.

    Post summary

    The text announces CVE-2026-4987, describing how SureForms payment forms allow user-controlled amounts without server-side validation, affecting all versions up to 2.5.2, but it provides no PoC, exploit details, or patch information.

    1101139
    18 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-4987 - high 🚨 SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via form_id > The SureForms plugin for WordPress is vulnerable to payment amount validation bypass ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-4987 @pdnuclei #Nuclei...

    Post summary

    The tweet announces the discovery of CVE-2026-4987, describing a payment amount validation bypass in SureForms, and provides a link for further information.

    01010266
    1.1K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4987 - SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id' Intel Report: https://ift.tt/R3QH9N1

    Post summary

    The alert announces CVE‑2026‑4987 in SureForms 2.5.2 and later, detailing an unauthenticated bypass of payment amount validation via the form_id parameter. No exploit, patch, or PoC is referenced.

    0000035
    283 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4987 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4987 #CVE-2026-4987 #CVE #High #Wordpress #CyberSecurity #InfoSec https://t.co/6UflUSYZjl

    Post summary

    The post announces a new WordPress CVE (CVE‑2026‑4987) with a severity score of 7.5 and references the NVD entry for details.

    0000045
    123 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4987 - SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id' Intel Report: https://ift.tt/J7FUsdf

    Post summary

    The alert announces CVE-2026-4987 in SureForms (≤2.5.2), detailing an unauthenticated payment amount validation bypass via 'form_id'. No PoC, exploit code, active exploitation, or patch information is provided.

    0000043
    283 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4987 - SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id' Intel Report: https://ift.tt/GfqDoAw

    Post summary

    A new vulnerability (CVE-2026-4987) affecting SureForms devices up to version 2.5.2 is announced, enabling unauthenticated users to bypass payment amount validation through the 'form_id' parameter. No exploit, patch, or active exploitation details are provided.

    0000043
    283 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4987 The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amount Bypass in all versions up to, and including,… https://www.cve.org/CVERecord?id=CVE-2026-4987

    Post summary

    The post announces CVE‑2026‑4987, a Payment Amount Bypass vulnerability affecting all versions of the SureForms WordPress plugin, and directs readers to the official CVE record.

    00000179
    56.9K followersView on X

Explore more