Junglewise Threat Intelligence

CVE-2026-66634: Modal Survey Insecure Direct Object References (IDOR) in Subscriber endpoints

CVE-2026-66634 · Severity: medium · CVSS 4.3 · Published 2026-08-18

Executive brief

Modal Survey is a WordPress plugin used to create and manage surveys on websites. This vulnerability allows authenticated subscribers (low-privilege users) to access and view other users' survey data by manipulating object identifiers in URLs, potentially exposing sensitive information submitted through surveys.

Technical details

The vulnerability is an Insecure Direct Object Reference (IDOR) flaw in the Modal Survey WordPress plugin affecting versions up to 2.0.2.2.3. The plugin fails to properly validate authorization when accessing subscriber-related endpoints, allowing an authenticated subscriber-level user to enumerate and retrieve other users' data by directly manipulating object IDs in requests. The attack requires subscriber-level authentication and network access to the affected WordPress instance. An attacker can view other subscribers' survey responses and associated data. No official patch is currently available as of the advisory publication date.

Affected products

  • Modal Survey Modal Survey <=2.0.2.2.3

Timeline

  • 2026-07-03: disclosed: Vulnerability reported by luc
  • 2026-08-18: advisory: Published by Patchstack

References