CVE-2025-64276: WordPress Survey Maker plugin <= 5.1.9.4 - Broken Access Control vulnerability
Missing Authorization vulnerability in Ays Pro Survey Maker survey-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Survey Maker: from n/a through <= 5.1.9.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64276?
CVE-2025-64276 is classified as a high-severity vulnerability due to its potential to exploit missing authorization controls.
How do I fix CVE-2025-64276?
To fix CVE-2025-64276, update Ays Pro Survey Maker to version 5.1.9.5 or later where the vulnerability is patched.
What versions are affected by CVE-2025-64276?
CVE-2025-64276 affects Ays Pro Survey Maker versions up to and including 5.1.9.4.
Who is impacted by CVE-2025-64276?
Users of Ays Pro Survey Maker and the WordPress Survey Maker plugin who are running versions up to 5.1.9.4 are impacted by CVE-2025-64276.
What type of vulnerability is CVE-2025-64276?
CVE-2025-64276 is categorized as a missing authorization vulnerability that allows exploiting incorrectly configured access control security levels.