SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-5626

MEDIUM · CVSS 4.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The Survey Form Block plugin for WordPress is vulnerable due to a lack of capability checks in the get_all_data() function, allowing authenticated users with Subscriber-level access or higher to export all survey submission data and associated metadata. This vulnerability poses a risk of unauthorized data exposure, which could lead to privacy breaches or data misuse. WordPress site administrators using this plugin should prioritize applying updates or implementing mitigations to safeguard sensitive survey data.

CVE
CVE-2026-5626
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%
WordPress

Original NVD Description

The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_data() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export all survey submission data and column metadata.