Missing Authorization Vulnerability in Ays Pro Survey Maker from Ays Pro
CVE-2025-64276

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 November 2025

What is CVE-2025-64276?

Ays Pro Survey Maker has a missing authorization vulnerability that allows attackers to exploit incorrectly configured access control security levels. This flaw can potentially lead to unauthorized access for users, enabling them to manipulate survey data or gain insights that they shouldn't have access to, affecting data integrity and user privacy. The issue affects versions of Survey Maker from the earliest release through 5.1.9.4.

Affected Version(s)

Survey Maker <= n/a

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo | Patchstack Bug Bounty Program
.
CVE-2025-64276 : Missing Authorization Vulnerability in Ays Pro Survey Maker from Ays Pro