← WordPress Vulnerabilities
WordPress security by component

SurveyFunnel – Survey Plugin for

SurveyFunnel – Survey Plugin for is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Dec 05, 2025; the highest CVE/CNA score is 6.4.

Plugin slug: surveyfunnel-lite

CVE-2025-13006: SurveyFunnel – Survey Plugin for: Sensitive information exposure

SurveyFunnel – Survey Plugin for is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.

PublishedDec 05, 2025
Safe version guidanceSee mitigation notes
Safe version
Dec 05, 2025 CVE-2025-13006
SurveyFunnel – Survey Plugin for: Sensitive information exposure
SurveyFunnel – Survey Plugin for is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVDPending
Dec 05, 2025 CVE-2025-12417
SurveyFunnel – Survey Plugin for: Cross-site scripting
SurveyFunnel – Survey Plugin for is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending