Unauthorized Data Access in Survey Form Block Plugin for WordPress
CVE-2026-5626

4.3MEDIUM

What is CVE-2026-5626?

The Survey Form Block plugin for WordPress contains a vulnerability that allows authenticated attackers with Subscriber-level access and above to access unauthorized survey data. This is due to a missing capability check in the get_all_data() function, which permits the export of all survey submissions and their associated metadata. The flaw exists in all versions up to and including 1.0.1, posing a significant risk of data exposure for users leveraging this plugin.

Affected Version(s)

Survey Form Block – collect answers and insights from your audience 0 <= 1.0.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Itthidej Aramsri (Boeing777)
.