Survey Maker WordPress Plugin Missing Authorization Vulnerability Allowing Unauthenticated Option Updates
Vulnerability
A vulnerability exists in the Survey Maker plugin for WordPress, in all versions through 5.1.9.4, allowing unauthenticated users to modify data. This issue arises from a lack of proper capability checks in the deactivate_plugin_option() function, which enables unauthorized attackers to change the ays_survey_maker_upgrade_plugin option.
Impact
Exploitation of this vulnerability allows for unauthorized, unauthenticated users to modify specific plugin options, potentially leading to unauthorized changes in plugin behavior or functionality.
Remediation
Users are advised to update the Survey Maker plugin to version 5.1.9.5 or later.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
