Survey Maker WordPress Plugin Missing Authorization Vulnerability Allowing Unauthenticated Option Updates

Vulnerability

A vulnerability exists in the Survey Maker plugin for WordPress, in all versions through 5.1.9.4, allowing unauthenticated users to modify data. This issue arises from a lack of proper capability checks in the deactivate_plugin_option() function, which enables unauthorized attackers to change the ays_survey_maker_upgrade_plugin option.

Impact

Exploitation of this vulnerability allows for unauthorized, unauthenticated users to modify specific plugin options, potentially leading to unauthorized changes in plugin behavior or functionality.

Remediation

Users are advised to update the Survey Maker plugin to version 5.1.9.5 or later.

Added: Nov 13, 2025, 4:17 AM
Updated: Nov 13, 2025, 4:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.1
remediation
7.7
relevance
1.0
threat
3.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.