The SureForms plugin for WordPress is vulnerable to payment amount validation bypass in versions up to, and including, 2.5.2.
The create_payment_intent AJAX handler checks `if ($form_id > 0 && !empty($block_id))` before calling validate_payment_amount().
By sending form_id=0 (the default intval of a missing/zero value), an unauthenticated attacker completely skips the server-side
amount validation and can create Stripe payment intents with arbitrary amounts, bypassing configured pricing.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view