CVE-2026-85308 Authorization Bypass Through User-Controlled Key… — CVE Notify — TG.ME

🚨 CVE-2026-85308
Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects SureForms: from n/a through 2.12.5.

🎖@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress SureForms Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
September 3, 2026 34