CVE-2025-12891: Survey Maker <= 5.1.9.4 - Missing Authorization to Unauthenticated Information Exposure
The Survey Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ayssurveyshowresults' AJAX endpoint in all versions up to, and including, 5.1.9.4. This makes it possible for unauthenticated attackers to view all survey submissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12891?
CVE-2025-12891 has a high severity rating due to the potential for unauthorized data access by unauthenticated users.
How do I fix CVE-2025-12891?
To fix CVE-2025-12891, update the Survey Maker plugin to version 5.1.9.5 or later.
What type of vulnerability is CVE-2025-12891?
CVE-2025-12891 is a vulnerability related to insufficient authorization checks on an AJAX endpoint.
Who is affected by CVE-2025-12891?
All users of the Survey Maker plugin for WordPress running versions up to and including 5.1.9.4 are affected by CVE-2025-12891.
What can attackers do with CVE-2025-12891?
Attackers can leverage CVE-2025-12891 to gain unauthorized access and view survey results without authentication.