Extension WordPress
Vulnérabilités UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds
Cette page rassemble les failles publiées pour UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds
9 fiches
User Feedback <= 1.10.1 – Missing Authorization
The User Feedback plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.10.1. This makes it possible for authenticated attackers, with subscriber-level access and…
*-1.10.1
1.11.0
18/03/2026
User Feedback <= 1.10.1 – Authenticated (Editor+) SQL Injection
The User Feedback plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.10.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
*-1.10.1
1.11.0
20/02/2026
User Feedback <= 1.10.0 – Authenticated (Editor+) SQL Injection
The User Feedback plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
*-1.10.0
1.10.1
22/12/2025
User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.8.0 – Missing Authorization to Information Disclosure
The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `maybe_load_onboarding_wizard` function in all versions up…
*-1.8.0
1.9.0
24/10/2025
UserFeedback Lite <= 1.0.15 – Unauthenticated Stored Cross-Site Scripting via Name Parameter
The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name parameter in all versions up to, and including, 1.0.15 due to insufficient…
*-1.0.15
1.0.16
12/07/2024
User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.0.13 – Unauthenticated Stored Cross-Site Scripting
The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_submitted' 'link' value in all versions up to, and including, 1.0.13 due to…
*-1.0.13
1.0.14
21/02/2024
User Feedback <= 1.0.10 – Missing Authorization
The User Feedback plugin for WordPress is vulnerable to unauthorized access of data due to insufficient authorization checking on the save_survey_response function in versions up to, and including, 1.0.10. This makes it possible for unauthenticated attackers to provide…
*-1.0.10
1.0.11
26/12/2023
User Feedback <= 1.0.9 – Unauthenticated Cross-Site Scripting
The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Cross-Site Scripting via an unknown parameter in all versions up to, and including, 1.0.9 due to insufficient input…
*-1.0.9
1.0.10
17/10/2023
User Feedback <= 1.0.7 – Unauthenticated Stored Cross-Site Scripting
The User Feedback plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user responses for surveys in versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-1.0.7
1.0.8
04/09/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.