CVE-2026-19500 is a denial-of-service vulnerability in the Entries component of Brainstorm Force SureForms before version 2.1.3. The flaw stems from inadequate enforcement of limits on user-controlled form fields or submitted content during processing and rendering. By submitting crafted form data designed to consume excessive application or server resources, a remote attacker can cause the affected component to become unstable and fail while handling entry data, including when administrators attempt to access the Entries interface.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept for CVE-2026-19500 affecting the SureForms WordPress plugin. The repo contains only three files: a README describing the denial-of-service issue, a funding YAML file, and the exploit script pocdos.py. The exploit is not part of a larger framework. The main capability is application-layer DoS against SureForms form handling/storage. The script constructs a POST request to the WordPress REST endpoint /index.php/wp-json/sureforms/v1/submit-form, supplies a valid form-id and X-WP-Submit-Token header, and then appends a large number of attacker-controlled form fields. Each field name is derived from a base64-encoded counter, and each field value contains repeated HTML-encoded img tags referencing an attacker-supplied page URL. This inflates the submission size and number of key/value pairs, matching the README’s claim that unlimited key-value submission leads to resource exhaustion and prevents administrators from viewing entries temporarily. Code structure is simple: to_base64() encodes strings for field-name generation; poc() builds the malicious payload, sets the _locale=user parameter and token header, then sends the POST request with requests.post(); the __main__ block contains commented interactive inputs plus hardcoded example values for URL, form ID, token, page, and repetition count. There is no shell, code execution, persistence, or lateral movement capability—only repeated malformed/oversized form submission for denial of service. The exploit is operational because it contains working request logic and a hardcoded example target, but it is still a basic PoC rather than a weaponized framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.