Impact
The Survey Maker plugin for WordPress contains a missing capability check on the 'ays_survey_show_results' AJAX endpoint in all versions up to 5.1.9.4. This flaw allows unauthenticated users to retrieve all survey submissions through the exposed endpoint. As a result, attacker confidentiality can be breached, allowing disclosure of potentially sensitive survey data without authentication or authorization.
Affected Systems
All instances of the Survey Maker plugin installed on WordPress sites that are running version 5.1.9.4 or earlier are affected. The vulnerability is present in each version up to and including 5.1.9.4 of the plugin, regardless of the WordPress core version.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, so there is no current evidence of known exploitation. However, because the attack vector is a public web‑facing AJAX endpoint and is exploitable without authentication, the risk to sites that are exposed to the internet remains real. The impact is limited to information disclosure; there is no known path to code execution or denial of service.
OpenCVE Enrichment