Survey Maker WordPress Plugin Missing Authorization Vulnerability Allowing Unauthenticated Data Exposure
Vulnerability
A vulnerability exists in the Survey Maker plugin for WordPress, in all versions through 5.1.9.4, due to a lack of proper capability checks on the 'ays_survey_show_results' AJAX endpoint. This flaw enables unauthenticated attackers to access and view all survey submissions.
Impact
Exploitation of this vulnerability allows for unauthorized access to survey data, exposing all survey submissions to unauthenticated users.
Remediation
Users are advised to update the Survey Maker plugin to version 5.1.9.5 or a newer patched version.
Added: Nov 13, 2025, 5:18 AM
Updated: Nov 13, 2025, 5:18 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
8.1remediation
7.7relevance
1.0threat
3.2urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
