First published: Fri Apr 04 2025(Updated: )
Missing Authorization vulnerability in devsoftbaltic SurveyJS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects SurveyJS: from n/a through 1.12.20.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
SurveyJS | <=1.12.20 | |
WordPress SurveyJS plugin | <=1.12.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32256 is categorized as a missing authorization vulnerability that can lead to unauthorized access.
To fix CVE-2025-32256, upgrade the SurveyJS product or WordPress SurveyJS plugin to version 1.12.21 or later.
CVE-2025-32256 affects SurveyJS versions from n/a to 1.12.20, including the WordPress SurveyJS plugin.
Attackers can access functionality not properly constrained by ACLs, potentially compromising sensitive data.
No formal workaround exists; the recommended action is to upgrade to a patched version.