CVE-2025-13528: Feedback Modal for Website <= 1.0.1 - Missing Authorization to Unauthenticated Arbitrary Feedback Data Exfiltration via 'export_data' Parameter
The Feedback Modal for Website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handleexport' function in all versions up to, and including, 1.0.1. This makes it possible for unauthenticated attackers to export all feedback data in CSV or JSON format via the 'exportdata' parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13528?
CVE-2025-13528 has a high severity rating due to the potential for unauthorized data access.
How do I fix CVE-2025-13528?
To fix CVE-2025-13528, update the WordPress Feedback Modal for Website plugin to version 1.0.2 or later.
Who is affected by CVE-2025-13528?
All users of the WordPress Feedback Modal for Website plugin versions up to and including 1.0.1 are affected by CVE-2025-13528.
What type of vulnerability is CVE-2025-13528?
CVE-2025-13528 is a security vulnerability that involves unauthorized access to data.
Can CVE-2025-13528 be exploited without authentication?
Yes, CVE-2025-13528 can be exploited by unauthenticated attackers, allowing them to export feedback data.