The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 8,477 live websites that are affected by CVE-2025-14855.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 8,477 live websites (93% of SureForms install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 51 versions ( 94% of all versions) |
| 2,866 websites | |
| 1,476 websites | |
| 692 websites | |
| 417 websites | |
| 301 websites | |
| 250 websites | |
| 235 websites | |
| 218 websites | |
| 183 websites | |
| 175 websites |
| .com | 4,128 websites |
| .de | 684 websites |
| .org | 406 websites |
| .net | 307 websites |
| .fr | 264 websites |
| .nl | 253 websites |
| .com.br | 168 websites |
| .co.uk | 158 websites |
| .pl | 140 websites |
| .it | 136 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****************.com | **,*** | ||
| **************.be | **,*** | ||
| ********.com | **,*** | ||
| **********.net | **,*** | ||
| **************.com | **,*** | ||
| ****************.com | **,*** | ||
| ************.org | ***,*** | ||
| *******************.com | ***,*** | ||
| *********.com | ***,*** | ||
| ***********.nl | ***,*** |
FAQ