What is CVE-2026-5626?
CVE-2026-5626 was discovered in the Survey Form Block plugin for WordPress. Due to a missing capability check in the 'get_all_data()' function, authenticated users with Subscriber-level access and above can export data without authorization. Updating the plugin to the latest version is recommended.
Azərbaycanca: CVE-2026-5626, WordPress üçün Survey Form Block plaginində aşkar edilib. "get_all_data()" funksiyasında capability check olmaması səbəbindən, Subscriber və yuxarı səviyyəli autentifikasiya olunmuş istifadəçilər icazəsiz məlumat ixrac edə bilərlər. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
In which WordPress plugin was CVE-2026-5626 discovered?
The CVE-2026-5626 vulnerability was discovered in the Survey Form Block plugin.
What level of authentication is required to exploit CVE-2026-5626?
To exploit this vulnerability, a user must be authenticated with at least Subscriber-level access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.