Cross-Site Request Forgery in SurveyJS Drag & Drop WordPress Form Builder
CVE-2025-13139

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 January 2026

What is CVE-2025-13139?

The SurveyJS Drag & Drop WordPress Form Builder plugin allows unauthenticated attackers to exploit a Cross-Site Request Forgery vulnerability due to a lack of nonce validation on the SurveyJS_AddSurvey AJAX action. By successfully tricking an administrator into executing an action, attackers can create unauthorized surveys. This vulnerability affects all versions of the plugin up to and including 1.12.20, posing security risks to WordPress sites using this plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

SurveyJS: Drag & Drop Form Builder * <= 1.12.20

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Nur Ibnu Hubab
.