PT-2025-46781 · WordPress · Survey Maker

German

·

Published

2025-11-13

·

Updated

2025-11-13

·

CVE-2025-12892

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Survey Maker plugin for WordPress versions up to and including 5.1.9.4
Description The software is susceptible to unauthorized data modification. This is due to a missing capability check within the deactivate plugin option() function. This allows unauthenticated attackers to update the ays survey maker upgrade plugin option.
Recommendations Update the Survey Maker plugin to a version later than 5.1.9.4.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-12892

Affected Products

Survey Maker