CVE-2026-5626
Received Received - Intake

Survey Form Block Plugin Data Exposure Vulnerability

Vulnerability report for CVE-2026-5626, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-29

Last updated on: 2026-07-29

Assigner: Wordfence

Description

The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_data() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export all survey submission data and column metadata.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-29
Last Modified
2026-07-29
Generated
2026-07-29
AI Q&A
2026-07-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
bplugins survey_form_block to 1.0.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Survey Form Block plugin for WordPress has a vulnerability where the get_all_data() function lacks a proper capability check. This allows authenticated users with Subscriber-level access or higher to export all survey submission data and column metadata without authorization.

Detection Guidance

To detect this vulnerability, check WordPress sites using the Survey Form Block plugin versions up to 1.0.1. Look for unauthorized export of survey submission data by authenticated users with Subscriber-level access or higher. Review server logs for suspicious API requests to the get_all_data() function endpoint.

Impact Analysis

If you use this plugin, attackers with basic WordPress access could steal sensitive survey responses and metadata. This could lead to data breaches, privacy violations, or misuse of collected information.

Compliance Impact

This vulnerability could violate GDPR by exposing personal data without consent and HIPAA by compromising protected health information if surveys collected such data. Organizations may face fines or legal consequences for non-compliance.

Mitigation Strategies

Immediately update the Survey Form Block plugin to version 1.0.2 or later. Remove or disable the plugin if an update is not possible. Restrict Subscriber-level user permissions to prevent unauthorized access. Monitor for any unusual data export activities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-5626. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart