plugin

Modal Survey Vulnerabilities

2 known security issues reported for the Modal Survey WordPress plugin. Most recent disclosed Jan 8, 2021.

1 critical 1 high

Running Modal Survey on your site? Check whether your installed version is affected.

Scan your site free

Modal Survey <= 2.0.1.8 - PHP Object Injection

critical

The Modal Survey plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.1.8 via deserialization of untrusted input using the unserialize() function. This allows authenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to remotely t...

CVSS:
9.1
Affected:
up to 2.0.1.8
Fixed in:
2.0.1.8.2
Disclosed:
Jan 8, 2021

Modal Survey < 2.0.1.8.2 - Authorization Bypass

high

The Modal Survey Plugin for WordPress is vulnerable to Arbitrary Survey Update, Deletion and Creation in versions before 2.0.1.8.2 via the 'ajax_survey' AJAX action due to lacking capability checks. This allows unauthenticated attackers to create, update, or delete arbitrary surveys.

CVSS:
7.5
Affected:
up to 2.0.1.8.2
Fixed in:
2.0.1.8.2
Disclosed:
Jan 8, 2021

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database