Unauthorized Data Access in Feedback Modal for Website Plugin by WordPress
CVE-2025-13528
What is CVE-2025-13528?
The Feedback Modal for Website plugin for WordPress contains a vulnerability that allows unauthorized users to access sensitive data. The issue arises from a lack of capability checks in the 'handle_export' function, which affects all versions up to and including 1.0.1. This flaw enables unauthenticated attackers to exploit the 'export_data' parameter, leading to the potential export of all feedback data in formats such as CSV or JSON. Users of the plugin should take immediate action to mitigate this risk and secure their data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Feedback Modal for Website * <= 1.0.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved