Feedback Modal for Website <= 1.0.1 - Unauthenticated Feedback Export
CVE-2025-13528
Verified
Description
The Feedback Modal for Website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_export' function in all versions up to, and including, 1.0.1. This makes it possible for unauthenticated attackers to export all feedback data in CSV or JSON format via the 'export_data' parameter.
Severity
Medium
Exploit Probability
1%
Published Date
August 10, 2026
Template Author
coffeetaro_12
CVE-2025-13528.yaml
5.0Severity
CVSS Metrics
CVE ID:
cve-2025-13528
CWE ID:
cwe-862
Remediation Steps
Update to the latest version beyond 1.0.1.