CVE-2025-12892: Survey Maker <= 5.1.9.4 - Missing Authorization to Unauthenticated Limited Option Update
The Survey Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivatepluginoption() function in all versions up to, and including, 5.1.9.4. This makes it possible for unauthenticated attackers to update the ayssurveymakerupgradeplugin option.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12892?
The severity of CVE-2025-12892 is critical due to unauthorized data modification risks.
How do I fix CVE-2025-12892?
To fix CVE-2025-12892, update the Survey Maker plugin to version 5.1.9.5 or later.
Who is affected by CVE-2025-12892?
Users of the Survey Maker plugin for WordPress up to version 5.1.9.4 are affected by CVE-2025-12892.
What kind of attacks can occur due to CVE-2025-12892?
CVE-2025-12892 allows unauthenticated attackers to modify plugin settings and data without authorization.
Is there a workaround for CVE-2025-12892?
There is no official workaround for CVE-2025-12892; updating the plugin is the recommended course of action.