CVE-2025-6742 Details
Description
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.3 via the use of file_exists() in the delete_entry_files() function without restriction on the path provided. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
A PHP Object Injection vulnerability has been identified in the SureForms - Drag and Drop Form Builder for WordPress plugin, affecting all versions prior to 1.7.4. The vulnerability arises in the delete_entry_files() function, where file_exists() is used without proper path restrictions. This flaw allows unauthenticated attackers to inject PHP objects. While the vulnerable plugin itself does not have a known object injection chain, the vulnerability could be exploited if another plugin or theme with a compatible chain is installed, potentially leading to unauthorized file deletions, data retrieval, or code execution.
Users are advised to update the SureForms WordPress plugin to version 1.7.4 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| brainstormforce sureforms | >= 0.0.2, < 0.0.14 >= 1.0.0, < 1.0.7 >= 1.1.0, < 1.1.2 >= 1.2.0, < 1.2.5 >= 1.3.0, < 1.3.2 >= 1.4.0, < 1.4.5 >= 1.6.0, < 1.6.5 >= 1.7.0, < 1.7.4 1.5.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 11, 2025 | Initial Analysis | [email protected] |
| Jul 9, 2025 | New CVE Received | [email protected] |