SureForms Pro is a WordPress plugin commonly used to collect customer data, leads, and inquiries; a missing authorization flaw means attackers may access submitted form data or restricted plugin functions without permission. Depending on what data the affected forms collect, this could expose customer contact information, internal submissions, or configuration details, creating potential liability under applicable data protection requirements. While exploitation in the wild appears low at present, the high CVSS score means the attack is feasible with minimal effort once a target is identified.
You Are Affected If
You run Brainstorm Force SureForms Pro version 2.8.0 or earlier on any WordPress installation
The affected WordPress site is internet-facing and does not have a WAF blocking unauthorized plugin endpoint access
The plugin is active (not merely installed) on a site that collects or stores user-submitted data
You have not yet applied a SureForms Pro update released after 2.8.0 that addresses CVE-2026-42377
Your WordPress environment grants unauthenticated or subscriber-level users access to REST API or ajax endpoints without additional access controls
Board Talking Points
A security flaw in a widely used WordPress form plugin allows unauthorized access to restricted data or functions on affected websites.
Technology teams should audit all WordPress sites using SureForms Pro and apply the available update within the next patch cycle.
Without remediation, the flaw could be exploited to access customer submissions or site data, creating potential legal and reputational exposure.
GDPR / regional data protection law — SureForms Pro collects form submissions that may include personal data; unauthorized access to that data could constitute a reportable breach depending on what information the forms collect