PT-2026-65687 · Bplugins · Survey Form Block – Collect Answers/Insights From Your Audience

·

CVE-2026-5626

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get all data() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export all survey submission data and column metadata.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5626

Affected Products

Survey Form Block – Collect Answers/Insights From Your Audience