Junglewise Threat Intelligence

CVE-2026-39475: Syed Balkhi User Feedback blind SQL injection

CVE-2026-39475 · Severity: high · CVSS 7.6 · Published 2026-04-08

Executive brief

The User Feedback plugin for WordPress, used to collect visitor insights and surveys, is vulnerable to a blind SQL injection attack. A malicious user with high-level privileges (such as an Editor) could exploit this to interact directly with the website's database. This could lead to the unauthorized extraction of sensitive information, including user data and site configurations.

Technical details

A blind SQL injection vulnerability exists in the Syed Balkhi User Feedback (userfeedback-lite) plugin for WordPress due to improper neutralization of special elements in SQL commands (CWE-89). The flaw affects versions up to and including 1.10.1. An attacker with high-level administrative privileges (Editor or higher) can send specially crafted network requests to trigger the vulnerability. Successful exploitation allows the attacker to perform blind SQL queries against the backend database, potentially leading to full data exfiltration. The issue is resolved in version 1.11.0.

Affected products

  • Syed Balkhi User Feedback / userfeedback-lite <= 1.10.1

Timeline

  • 2026-01-21: disclosed: Reported by Nguyen Ba Khanh
  • 2026-02-20: patched: Patch released in version 1.11.0
  • 2026-04-08: advisory: CVE published

References

Related threats