Cross-Site Scripting Vulnerability in Survey Maker Plugin by WordPress
CVE-2026-26370
5.1MEDIUM
What is CVE-2026-26370?
The Survey Maker plugin for WordPress has a vulnerability that allows for cross-site scripting attacks. In versions 5.1.7.7 and earlier, an attacker can exploit this flaw to inject arbitrary scripts into user sessions. When users interact with compromised parts of the plugin, malicious scripts can execute in their browsers, potentially compromising sensitive data and user accounts. Website administrators should ensure they are using an updated version of the plugin to safeguard against these types of attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Survey Maker 5.1.7.7 and prior
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
CVSS V3.0
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved