Skip to main content
Vulnerability Database/CVE-2025-10732

CVE-2025-10732: SureForms WordPress Plugin Data Leak

CVE-2025-10732 is an information disclosure flaw in SureForms WordPress plugin that exposes API keys and admin email addresses to contributors. This article covers the technical details, affected versions, and steps to secure your installation.

Published:

CVE-2025-10732 Overview

CVE-2025-10732 is a sensitive information disclosure vulnerability in the SureForms – Drag and Drop Form Builder plugin for WordPress. The flaw affects all versions up to and including 1.12.1. The issue stems from improper access control on the /wp-json/sureforms/v1/srfm-global-settings REST API endpoint. Authenticated users with contributor-level access or higher can retrieve sensitive plugin configuration data. Exposed data includes API keys for Google reCAPTCHA, Cloudflare Turnstile, and hCaptcha, along with administrator email addresses and security-related form settings. The vulnerability is classified as [CWE-862] Missing Authorization.

Critical Impact

Low-privileged contributor accounts can extract CAPTCHA integration secrets and administrator email addresses, enabling downstream abuse of anti-bot protections and targeted phishing against site administrators.

Affected Products

  • SureForms – Drag and Drop Form Builder for WordPress plugin
  • All versions up to and including 1.12.1
  • WordPress installations with contributor-level or higher user accounts

Discovery Timeline

  • 2025-10-14 - CVE-2025-10732 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-10732

Vulnerability Analysis

The SureForms plugin registers a REST API route at /wp-json/sureforms/v1/srfm-global-settings to expose plugin configuration to the WordPress admin interface. The route handler does not enforce an administrative capability check before returning the settings payload. Any authenticated user session that WordPress accepts as valid, including contributor accounts, can invoke the endpoint. The response includes plaintext third-party service credentials that the site owner configured for spam and bot mitigation. Exposure of these secrets undermines the integrity of CAPTCHA challenges relying on them.

Root Cause

The root cause is a missing authorization check in the REST route registration for global settings. The permission_callback associated with the endpoint does not restrict access to users holding the manage_options capability. As a result, WordPress applies only the baseline authenticated-user check, allowing any account above the subscriber tier to read the configuration. The referenced source lines at inc/global-settings/global-settings.php#L64 and #L314 show where the endpoint is registered and where sensitive settings are returned.

Attack Vector

Exploitation requires an authenticated session at contributor level or above on a WordPress site running a vulnerable SureForms release. The attacker sends an authenticated HTTP GET request to /wp-json/sureforms/v1/srfm-global-settings and parses the JSON response. No user interaction from an administrator is required. The retrieved reCAPTCHA, Turnstile, and hCaptcha keys can then be reused off-site to bypass or abuse the site's bot protections, and disclosed admin emails can seed targeted phishing.

No verified proof-of-concept code is available in the referenced sources. See the Wordfence Vulnerability Overview and the SureForms Changeset Analysis for the fix details.

Detection Methods for CVE-2025-10732

Indicators of Compromise

  • Unexpected HTTP GET requests to /wp-json/sureforms/v1/srfm-global-settings originating from contributor, author, or editor accounts.
  • Access log entries for the SureForms global settings REST route from IP addresses not previously associated with administrative activity.
  • Reuse of the site's reCAPTCHA, Turnstile, or hCaptcha site or secret keys from unfamiliar external domains or clients.

Detection Strategies

  • Enable WordPress REST API request logging and alert on /wp-json/sureforms/v1/* calls made by non-administrator roles.
  • Correlate authentication events with subsequent REST API access to identify low-privileged accounts probing settings endpoints.
  • Baseline normal contributor and author behavior; treat any settings or configuration endpoint access as an anomaly worth review.

Monitoring Recommendations

  • Ingest WordPress and web server logs into a centralized analytics platform and retain them long enough to investigate credential misuse after the fact.
  • Monitor CAPTCHA vendor dashboards for unusual traffic patterns tied to your site keys that may indicate exposed secrets are being replayed.
  • Alert on the creation or elevation of contributor-level accounts on sites running the SureForms plugin.

How to Mitigate CVE-2025-10732

Immediate Actions Required

  • Update the SureForms plugin to a version later than 1.12.1 that contains the referenced patch changeset.
  • Rotate all API keys and secrets exposed through the endpoint, including Google reCAPTCHA, Cloudflare Turnstile, and hCaptcha credentials.
  • Review WordPress user accounts and remove or downgrade contributor-level and higher accounts that are no longer required.
  • Audit recent REST API access logs for requests to /wp-json/sureforms/v1/srfm-global-settings prior to patching.

Patch Information

The vendor addressed the missing authorization issue in the SureForms plugin. Review the SureForms Changeset Analysis for the code-level fix and the Wordfence Vulnerability Overview for the fixed version guidance. Vulnerable code paths are documented in the SureForms 1.12.0 global-settings.php line 64 and line 314 references.

Workarounds

  • If immediate patching is not possible, restrict access to the WordPress REST API using a security plugin or a web application firewall rule that blocks non-administrator access to /wp-json/sureforms/v1/*.
  • Temporarily deactivate the SureForms plugin on sites where contributor or author accounts exist and cannot be trusted.
  • Remove third-party CAPTCHA secret keys from the plugin configuration until an upgrade and key rotation can be performed.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.