User Feedback <= 1.10.1 - Missing Authorization
medium
The User Feedback plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.10.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.10.1
- Fixed in:
- 1.11.0
- Disclosed:
- Mar 18, 2026
CVE-2026-39476 on NVD →
User Feedback <= 1.10.1 - Authenticated (Editor+) SQL Injection
medium
The User Feedback plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.10.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level access and above,...
- CVSS:
- 4.9
- Affected:
- up to 1.10.1
- Fixed in:
- 1.11.0
- Disclosed:
- Feb 20, 2026
CVE-2026-39475 on NVD →
User Feedback <= 1.10.0 - Authenticated (Editor+) SQL Injection
medium
The User Feedback plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level access and above,...
- CVSS:
- 4.9
- Affected:
- up to 1.10.0
- Fixed in:
- 1.10.1
- Disclosed:
- Dec 22, 2025
CVE-2025-68496 on NVD →
User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.8.0 - Missing Authorization to Information Disclosure
medium
The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `maybe_load_onboarding_wizard` function in all versions up to, and including, 1.8.0. This makes it possible for unauthentica...
- CVSS:
- 5.3
- Affected:
- up to 1.8.0
- Fixed in:
- 1.9.0
- Disclosed:
- Oct 24, 2025
CVE-2025-10694 on NVD →
UserFeedback Lite <= 1.0.15 - Unauthenticated Stored Cross-Site Scripting via Name Parameter
high
The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name parameter in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenti...
- CVSS:
- 7.2
- Affected:
- up to 1.0.15
- Fixed in:
- 1.0.16
- Disclosed:
- Jul 12, 2024
CVE-2024-5902 on NVD →
User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.0.13 - Unauthenticated Stored Cross-Site Scripting
medium
The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_submitted' 'link' value in all versions up to, and including, 1.0.13 due to insufficient input sanitization and output escaping. This makes it possible...
- CVSS:
- 5.4
- Affected:
- up to 1.0.13
- Fixed in:
- 1.0.14
- Disclosed:
- Feb 21, 2024
CVE-2024-0903 on NVD →
User Feedback <= 1.0.10 - Missing Authorization
medium
The User Feedback plugin for WordPress is vulnerable to unauthorized access of data due to insufficient authorization checking on the save_survey_response function in versions up to, and including, 1.0.10. This makes it possible for unauthenticated attackers to provide feedback on unpublished surveys.
- CVSS:
- 5.3
- Affected:
- up to 1.0.10
- Fixed in:
- 1.0.11
- Disclosed:
- Dec 26, 2023
CVE-2023-50887 on NVD →
User Feedback <= 1.0.9 - Unauthenticated Cross-Site Scripting
high
The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Cross-Site Scripting via an unknown parameter in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated...
- CVSS:
- 7.2
- Affected:
- up to 1.0.9
- Fixed in:
- 1.0.10
- Disclosed:
- Oct 17, 2023
CVE-2023-46153 on NVD →
User Feedback <= 1.0.7 - Unauthenticated Stored Cross-Site Scripting
high
The User Feedback plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user responses for surveys in versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will e...
- CVSS:
- 7.2
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.8
- Disclosed:
- Sep 4, 2023
CVE-2023-39308 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database