Unauthorized Data Access in Survey Form Block Plugin for WordPress
CVE-2026-5626
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 July 2026
What is CVE-2026-5626?
The Survey Form Block plugin for WordPress contains a vulnerability that allows authenticated attackers with Subscriber-level access and above to access unauthorized survey data. This is due to a missing capability check in the get_all_data() function, which permits the export of all survey submissions and their associated metadata. The flaw exists in all versions up to and including 1.0.1, posing a significant risk of data exposure for users leveraging this plugin.
Affected Version(s)
Survey Form Block β collect answers and insights from your audience 0 <= 1.0.1