Junglewise Threat Intelligence

CVE-2026-80433: SureFeedback Client Site sensitive data exposure

CVE-2026-80433 · Severity: high · CVSS 7.5 · Published 2026-08-27

Vendors: Brainstorm Force.

Executive brief

SureFeedback Client Site is a WordPress plugin for collecting customer feedback. The plugin fails to properly restrict access to sensitive subscriber data, allowing attackers with subscriber-level privileges to expose private information such as passwords, emails, and other personal details. This vulnerability could lead to account compromise, identity theft, or further attacks against affected users.

Technical details

The vulnerability is classified as sensitive data exposure and affects WordPress SureFeedback Client Site plugin versions up to 1.2.12. The root cause is improper access control that allows subscribers (low-privilege users) to access sensitive data they should not be authorized to view. The attack vector is network-based and requires subscriber-level privileges, meaning an attacker must have a valid subscriber account or trick one into performing an action. An attacker can extract private information including passwords, emails, and payment details. The vulnerability has been patched in version 1.2.13 and later.

Affected products

  • Brainstorm Force SureFeedback Client Site <=1.2.12

Timeline

  • 2026-08-26: disclosed: Vulnerability published by Patchstack
  • 2026-08-26: patched: Patch available in version 1.2.13 and later

References