CVE-2025-14855

SureForms <= 2.2.0 - Unauthenticated Stored Cross-Site Scripting

The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 8,477 live websites that are affected by CVE-2025-14855.

Run a Free Instant Scan




Affected Software

Product  SureForms
Category Wordpress Plugins
Vulnerable Domains8,477 live websites (93% of SureForms install base)
Vulnerable Versions
  • from 0 through 2.2
Vulnerable Versions Count51 versions ( 94% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Dec 21, 2025
  • Updated - Dec 22, 2025

Credits

  • Tiến Dũng Nguyễn (finder)

Website Distribution by Country

Number of websites using CVE-2025-14855
United States2,866 websites



Germany1,476 websites
Cyprus692 websites
France417 websites
GB301 websites
Netherlands250 websites
India235 websites
Canada218 websites
Spain183 websites
Poland175 websites

Website Distribution by TLD

Number of websites using CVE-2025-14855
.com4,128 websites
.de684 websites
.org406 websites
.net307 websites
.fr264 websites
.nl253 websites
.com.br168 websites
.co.uk158 websites
.pl140 websites
.it136 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-14855

Top websites that are affected by CVE-2025-14855. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****************.com United States**,***
**************.be Belgium**,***
********.com United States**,***
**********.net United States**,***
**************.com United States**,***
****************.com United States**,***
************.org Germany***,***
*******************.com Bulgaria***,***
*********.com United States***,***
***********.nl Netherlands***,***
See full domain list

FAQ

CVE-2025-14855 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in SureForms
A total of 8,477 websites have been identified as vulnerable to CVE-2025-14855, based on global website indexing conducted by WebTechSurvey.
The SureForms is affected by the CVE-2025-14855 vulnerability.
SureForms versions up to and including 2.2 are vulnerable to CVE-2025-14855.