The SureForms plugin for WordPress is vulnerable to payment amount validation bypass in versions up to, and including, 2.5.2.
The create_payment_intent AJAX handler checks `if ($form_id > 0 && !empty($block_id))` before calling validate_payment_amount().
By sending form_id=0 (the default intval of a missing/zero value), an unauthenticated attacker completely skips the server-side
amount validation and can create Stripe payment intents with arbitrary amounts, bypassing configured pricing.
登录后查看神龙缓存的 POC 文件快照
登录查看