Impact
The SurveyJS: Drag & Drop WordPress Form Builder plugin contains a Cross‑Site Request Forgery flaw in the SurveyJS_DeleteSurvey AJAX action because a nonce is not verified. An attacker can construct a forged request that, when executed by a site administrator who follows a malicious link, causes the targeted survey to be deleted without the administrator’s knowledge.
Affected Systems
WordPress sites that have installed the devsoftbaltic SurveyJS: Drag & Drop Form Builder plugin in any version up to and including 1.12.20 are vulnerable. The vulnerability applies to all instances where the plugin’s delete_survey AJAX endpoint is exposed, regardless of the site’s user roles or configurations.
Risk and Exploitability
The flaw has a CVSS score of 4.3, indicating low severity. The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it has not yet been widely exploited. Attackers would need to lure an administrator into clicking a crafted URL, which is a straightforward CSRF attack vector. While the impact is limited to the removal of survey data, it can still disrupt business processes and lose valuable user responses.
OpenCVE Enrichment