/Vulnerability Library

Feedback Modal for Website <= 1.0.1 - Unauthenticated Feedback Export

CVE-2025-13528
Verified

Description

The Feedback Modal for Website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_export' function in all versions up to, and including, 1.0.1. This makes it possible for unauthenticated attackers to export all feedback data in CSV or JSON format via the 'export_data' parameter.

Severity

Medium

Exploit Probability

1%

Published Date

August 10, 2026

Template Author

coffeetaro_12

CVE-2025-13528.yaml
5.0Severity

CVSS Metrics

CVE ID:
cve-2025-13528
CWE ID:
cwe-862

References

https://wpscan.com/vulnerability/fbba8734-482e-4c22-9ee9-12e807a68ccc/https://nvd.nist.gov/vuln/detail/CVE-2025-13528

Remediation Steps

Update to the latest version beyond 1.0.1.