Executive brief
The User Feedback plugin for WordPress, which allows site owners to collect feedback from visitors, contains a security flaw in its access control mechanisms. An authenticated user with low-level permissions, such as a subscriber, can bypass intended security restrictions to perform actions they should not be authorized to access. This could lead to unauthorized data exposure or minor administrative changes depending on the specific misconfigured security levels.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Syed Balkhi User Feedback (userfeedback-lite) plugin for WordPress. The flaw is rooted in incorrectly configured access control security levels within the plugin's functional components. An attacker authenticated with basic 'Subscriber' privileges can exploit this lack of validation to execute functions or access data intended for higher-privileged roles. The vulnerability is reachable over the network without user interaction. The issue is addressed in version 1.11.0.
Affected products
- Syed Balkhi User Feedback (userfeedback-lite) <= 1.10.1
Timeline
- 2026-02-09: disclosed: Reported by Trương Hữu Phúc via Patchstack
- 2026-03-18: advisory: Patchstack published advisory
- 2026-04-08: patched: CVE published and fix confirmed in version 1.11.0