CVE-2026-5626
The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_dat
CVSS
4.3
Medio
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 29 jul 2026 · Última mod.: 29 jul 2026 · CWE-862
Sin historial EPSS suficiente todavía.
The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_data() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export all survey submission data and column metadata.
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/survey-form-block/tags/1.0.1/inc/SVBAjax.php#L52
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/survey-form-block/trunk/inc/SVBAjax.php#L52
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3502334%40survey-form-block%2Ftrunk%2Finc%2FSVBAjax.php&old=3223297%40survey-form-block%2Ftrunk%2Finc%2FSVBAjax.php
- wordpress.orghttps://wordpress.org/plugins/survey-form-block/
- www.wordfence.comhttps://www.wordfence.com/threat-intel/vulnerabilities/id/e98d4f04-74cd-486f-bb2f-fad76895f386?source=cve
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-171664.3 MED—
———The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to modify site-wide payment settings — including WooCommerce payment enablement, cart redirect behavior, login requirements for checkout, confirmation page ID, and confirmed ticket statuses — that govern how all event bookings are processed.9hCVE-2026-547197.5 ALT—
———goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did not call findEffectiveACL or applyCustomAuth, allowing unauthenticated reads of files protected only by .goshs folder ACLs and block lists. This issue is fixed in version 2.1.1. This vulnerability exists due to an incomplete fix for CVE-2026-40189.12hCVE-2026-161847.0 ALT—
———IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.14hCVE-2026-492588.8 ALT—
———Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-operator CA scoping employed by the JSON API. This was partially addressed by GHSA-598g-h2vc-h5vg, but the changes were not implemented in the web read/mutation surface. Any authenticated non-admin operator (for example, one created via self-registration or OIDC) can access resources belonging to other operators. The host create/edit/mobile-bundle/network-create paths and all CA-management routes were already correctly scoped. A malicious operator could block or delete any other operator's host, or read any operator's hosts and networks. This issue has been fixed in version 0.3.6.15hCVE-2026-667515.4 MED—
———Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to archive any room on the server by sending a DELETE request to the rooms handler without ownership verification. Attackers can enumerate room IDs via the rooms listing endpoint and permanently archive private or password-protected rooms they cannot access, with no application-level recovery path requiring direct database intervention to restore.17hCVE-2026-667504.3 MED—
———Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows authenticated attackers to download file attachments from private and password-protected rooms they are not a member of by exploiting missing room membership checks in the file retrieval route. Attackers can enumerate adjacent MongoDB ObjectIds derived from a known file ID to recover files uploaded by other users, as the GET /files/:id/:name route in app/controllers/files.js only enforces login authentication without consulting room membership or the Room.canJoin check.17h