Description
Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.
Published: 2026-08-27
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to access sensitive subscriber information stored by the SureFeedback Client Site plugin. The flaw exists in all versions up to and including 1.2.12, leading to a disclosure of confidential data such as personal details, subscription status, or other private information managed by the plugin.

Affected Systems

WordPress installations that use the Brainstorm Force SureFeedback Client Site plugin version 1.2.12 or earlier are affected. This includes any site that has not upgraded to the latest version after the vulnerability was disclosed.

Risk and Exploitability

The CVSS score of 7.5 classifies the issue as high severity. While an EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the presence of a direct data exposure flaw suggests that an attacker could exploit it remotely by interacting with exposed plugin endpoints. The exact attack vector is not explicitly documented, but the plugin’s functionality indicates that accessing certain URLs or submitting requests could trigger the disclosure.

Generated by OpenCVE AI on August 27, 2026 at 10:21 UTC.

Remediation

Vendor Solution

Update the WordPress SureFeedback Client Site Plugin to the latest available version (at least 1.2.13).


OpenCVE Recommended Actions

  • Update the WordPress SureFeedback Client Site Plugin to version 1.2.13 or later.
  • Disable or remove the plugin if it is no longer required for site functionality.
  • Verify that no exposed endpoints remain and monitor the vendor’s updates for additional security patches.

Generated by OpenCVE AI on August 27, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.
Title WordPress SureFeedback Client Site plugin <= 1.2.12 - Sensitive Data Exposure vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-27T09:00:06.310Z

Reserved: 2026-08-26T10:52:23.490Z

Link: CVE-2026-80433

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T10:16:38.780

Modified: 2026-08-27T10:16:38.780

Link: CVE-2026-80433

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T10:30:06Z

Weaknesses