Junglewise Threat Intelligence

CVE-2021-47941: Modalsurvey Survey & Poll SQL injection in wp_sap cookie

CVE-2021-47941 · Severity: high · CVSS 8.2 · Published 2026-05-10

Executive brief

The Survey & Poll plugin for WordPress, which allows site owners to create interactive feedback forms, contains a security flaw. An unauthenticated attacker can exploit this vulnerability to access the website's underlying database. This could lead to the theft of sensitive information, including user credentials, customer data, and site configuration details.

Technical details

An SQL injection vulnerability exists in the Survey & Poll plugin (version 1.5.7.3) for WordPress due to improper neutralization of special elements in the 'wp_sap' cookie parameter (CWE-89). A remote, unauthenticated attacker can send specially crafted HTTP requests containing malicious SQL payloads within the cookie. Successful exploitation allows the attacker to execute arbitrary SQL commands against the backend database, enabling the extraction of sensitive data such as administrative usernames and password hashes. Public exploit code is available, demonstrating the ability to dump database tables and version information.

Affected products

  • Modalsurvey Survey & Poll 1.5.7.3

Timeline

  • 2021-09-07: disclosed: Exploit code published on Exploit-DB
  • 2026-05-10: advisory: CVE-2021-47941 published by VulnCheck/NVD

References