User Feedback WordPress Plugin Missing Authorization Vulnerability in Onboarding Wizard Function

Vulnerability

A vulnerability exists in the User Feedback WordPress plugin, specifically in versions through 1.8.0. The issue arises from a missing capability check in the 'maybe_load_onboarding_wizard' function, allowing unauthorized access to the onboarding wizard page. This flaw enables unauthenticated attackers to view sensitive configuration information, including the administrator's email address.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive configuration data, such as the administrator's email address.

Remediation

Users are advised to update the User Feedback WordPress plugin to version 1.9.0 or a newer patched version.

Added: Oct 25, 2025, 6:32 AM
Updated: Oct 25, 2025, 6:32 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.1
remediation
7.7
relevance
0.8
threat
3.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.