WordPress security by component
User Feedback
Plugin description
User Feedback is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Apr 08, 2026; the highest CVE/CNA score is 7.6.
Plugin slug:
userfeedback-liteLatest vulnerability
CVE-2026-39476: User Feedback: A security weakness
User Feedback is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.10.1.
| Safe version |
|
||
|---|---|---|---|
| Apr 08, 2026 |
CVE-2026-39476
User Feedback: A security weakness
User Feedback is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.10.1.
|
1.11.0 |
CVE4.3
NVDPending
|
| Apr 08, 2026 |
CVE-2026-39475
User Feedback: SQL injection
User Feedback is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.10.1.
|
1.11.0 |
CVE7.6
NVDPending
|
| Dec 24, 2025 |
CVE-2025-68496
User Feedback: SQL injection
User Feedback is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVDPending
|
| Dec 09, 2024 |
CVE-2023-50887
User Feedback: A security weakness
User Feedback is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jul 12, 2024 |
CVE-2024-5902
User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds: Cross-site scripting
User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Oct 27, 2023 |
CVE-2023-46153
Userfeedback Lite: Cross-site scripting
Userfeedback Lite is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Sep 29, 2023 |
CVE-2023-39308
Userfeedback Lite: Cross-site scripting
Userfeedback Lite is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|