plugin

Userfeedback Lite Vulnerabilities

9 known security issues reported for the Userfeedback Lite WordPress plugin. Most recent disclosed Mar 18, 2026.

3 high 6 medium

Running Userfeedback Lite on your site? Check whether your installed version is affected.

Scan your site free

User Feedback <= 1.10.1 - Missing Authorization

medium

The User Feedback plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.10.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.10.1
Fixed in:
1.11.0
Disclosed:
Mar 18, 2026

CVE-2026-39476 on NVD →

User Feedback <= 1.10.1 - Authenticated (Editor+) SQL Injection

medium

The User Feedback plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.10.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level access and above,...

CVSS:
4.9
Affected:
up to 1.10.1
Fixed in:
1.11.0
Disclosed:
Feb 20, 2026

CVE-2026-39475 on NVD →

User Feedback <= 1.10.0 - Authenticated (Editor+) SQL Injection

medium

The User Feedback plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level access and above,...

CVSS:
4.9
Affected:
up to 1.10.0
Fixed in:
1.10.1
Disclosed:
Dec 22, 2025

CVE-2025-68496 on NVD →

User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.8.0 - Missing Authorization to Information Disclosure

medium

The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `maybe_load_onboarding_wizard` function in all versions up to, and including, 1.8.0. This makes it possible for unauthentica...

CVSS:
5.3
Affected:
up to 1.8.0
Fixed in:
1.9.0
Disclosed:
Oct 24, 2025

CVE-2025-10694 on NVD →

UserFeedback Lite <= 1.0.15 - Unauthenticated Stored Cross-Site Scripting via Name Parameter

high

The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name parameter in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenti...

CVSS:
7.2
Affected:
up to 1.0.15
Fixed in:
1.0.16
Disclosed:
Jul 12, 2024

CVE-2024-5902 on NVD →

User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.0.13 - Unauthenticated Stored Cross-Site Scripting

medium

The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_submitted' 'link' value in all versions up to, and including, 1.0.13 due to insufficient input sanitization and output escaping. This makes it possible...

CVSS:
5.4
Affected:
up to 1.0.13
Fixed in:
1.0.14
Disclosed:
Feb 21, 2024

CVE-2024-0903 on NVD →

User Feedback <= 1.0.10 - Missing Authorization

medium

The User Feedback plugin for WordPress is vulnerable to unauthorized access of data due to insufficient authorization checking on the save_survey_response function in versions up to, and including, 1.0.10. This makes it possible for unauthenticated attackers to provide feedback on unpublished surveys.

CVSS:
5.3
Affected:
up to 1.0.10
Fixed in:
1.0.11
Disclosed:
Dec 26, 2023

CVE-2023-50887 on NVD →

User Feedback <= 1.0.9 - Unauthenticated Cross-Site Scripting

high

The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Cross-Site Scripting via an unknown parameter in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated...

CVSS:
7.2
Affected:
up to 1.0.9
Fixed in:
1.0.10
Disclosed:
Oct 17, 2023

CVE-2023-46153 on NVD →

User Feedback <= 1.0.7 - Unauthenticated Stored Cross-Site Scripting

high

The User Feedback plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user responses for surveys in versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will e...

CVSS:
7.2
Affected:
up to 1.0.7
Fixed in:
1.0.8
Disclosed:
Sep 4, 2023

CVE-2023-39308 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database