High severity8.8NVD Advisory· Published Feb 1, 2022· Updated Jun 17, 2026
CVE-2021-24763
CVE-2021-24763
Description
The Perfect Survey WordPress plugin before 1.5.2 does not have proper authorisation nor CSRF checks in the save_global_setting AJAX action, allowing unauthenticated users to edit surveys and modify settings. Given the lack of sanitisation and escaping in the settings, this could also lead to a Stored Cross-Site Scripting issue which will be executed in the context of a user viewing any survey
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<1.5.2+ 1 more
- (no CPE)range: <1.5.2
- (no CPE)
- cpe:2.3:a:getperfectsurvey:perfect_survey:*:*:*:*:*:wordpress:*:*Range: <1.5.2
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/c73c7694-1cee-4f26-a425-9c336adce52bnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.