Plugin Vulnerability Hub
Plugin 10 known issues Latest disclosed Mar 20, 2026

SurveyJS: Drag & Drop Form Builder Vulnerabilities

Review known vulnerability records for the WordPress plugin SurveyJS: Drag & Drop Form Builder (`surveyjs`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-2440, CVE-2025-13205 and CVE-2025-13194, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
10
High or Critical
3
Patch Coverage
100%
Last Updated
Apr 15, 2026
Priority CVE Quick Links

Fast paths into SurveyJS: Drag & Drop Form Builder CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
10
CVE-2024-12544 High 1.12.18
CVE-2024-12544 SurveyJS: Drag & Drop Form Builder Remote Code Execution

SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity <= 1.12.17 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion via SurveyJS_DeleteFile

CVE-2024-50427 High 1.12.4
CVE-2024-50427 SurveyJS: Drag & Drop Form Builder Remote Code Execution

SurveyJS: Drag & Drop WordPress Form Builder <= 1.9.136 - Authenticated (Subscriber+) Arbitrary File Upload

CVE-2026-2440 High No patch listed
CVE-2026-2440 SurveyJS: Drag & Drop Form Builder Stored Cross-Site Scripting

SurveyJS: Drag & Drop Form Builder <= 2.5.3 - Unauthenticated Stored Cross-Site Scripting

CVE-2025-3815 Medium 1.12.33
CVE-2025-3815 SurveyJS: Drag & Drop Form Builder Stored Cross-Site Scripting

SurveyJS <= 1.12.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter

CVE-2025-32167 Medium 1.12.57
CVE-2025-32167 SurveyJS: Drag & Drop Form Builder Stored Cross-Site Scripting

SurveyJS <= 1.12.20 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVE-2025-32256 Medium 1.12.57
CVE-2025-32256 SurveyJS: Drag & Drop Form Builder Vulnerability

SurveyJS <= 1.12.20 - Missing Authorization

CVE-2025-13205 Medium 2.5.3
CVE-2025-13205 SurveyJS: Drag & Drop Form Builder Cross-Site Request Forgery

SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity <= 2.5.2 - Cross-Site Request Forgery to Survey Cloning

CVE-2025-13194 Medium 2.5.3
CVE-2025-13194 SurveyJS: Drag & Drop Form Builder Cross-Site Request Forgery

SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity <= 2.5.2 - Cross-Site Request Forgery to Survey Renaming

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for SurveyJS: Drag & Drop Form Builder so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
10 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 3 high severity findings.
Recent CVEs
CVE-2026-2440, CVE-2025-13205 and CVE-2025-13194
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for SurveyJS: Drag & Drop Form Builder

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: No CVE-2026-2440
CVE-2026-2440: SurveyJS: Drag & Drop Form Builder <= 2.5.3 - Unauthenticated Stored Cross-Site Scripting

The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.3 via survey result submissions. This is due to insufficient input sanitization and output escaping. The public survey page exposes the nonce required for subm...

Published
Mar 20, 2026
Patched Release
Not published
Affected Versions
Versions up to 2.5.3
Next Step
Open the full report for remediation notes and references.
Plugin Medium Patched: Yes CVE-2025-13205
CVE-2025-13205: SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity <= 2.5.2 - Cross-Site Request Forgery to Survey Cloning

The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on the `...

Published
Jan 23, 2026
Patched Release
2.5.3
Affected Versions
Versions up to 2.5.2
Next Step
Update to 2.5.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-13194
CVE-2025-13194: SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity <= 2.5.2 - Cross-Site Request Forgery to Survey Renaming

The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing nonce verification on the 'SurveyJS_Re...

Published
Jan 23, 2026
Patched Release
2.5.3
Affected Versions
Versions up to 2.5.2
Next Step
Update to 2.5.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-13139
CVE-2025-13139: SurveyJS: Drag & Drop WordPress Form Builder <= 2.5.2 - Cross-Site Request Forgery to Survey Creation

The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing nonce validation on the SurveyJS_AddSurvey AJAX action. This makes it possible for unauthenticated...

Published
Jan 23, 2026
Patched Release
2.5.3
Affected Versions
Versions up to 2.5.2
Next Step
Update to 2.5.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-13140
CVE-2025-13140: SurveyJS: Drag & Drop WordPress Form Builder <= 1.12.20 - Cross-Site Request Forgery to Survey Deletion

The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12.20. This is due to missing nonce validation on the SurveyJS_DeleteSurvey AJAX action. This makes it possible for unauthenti...

Published
Dec 01, 2025
Patched Release
1.20.27
Affected Versions
Versions up to 1.12.20
Next Step
Update to 1.20.27 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-3815
CVE-2025-3815: SurveyJS <= 1.12.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter

The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.12.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-lev...

Published
May 02, 2025
Patched Release
1.12.33
Affected Versions
Versions up to 1.12.32
Next Step
Update to 1.12.33 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-32256
CVE-2025-32256: SurveyJS <= 1.12.20 - Missing Authorization

The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.12.20. This makes it poss...

Published
Apr 04, 2025
Patched Release
1.12.57
Affected Versions
Versions up to 1.12.20
Next Step
Update to 1.12.57 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-32167
CVE-2025-32167: SurveyJS <= 1.12.20 - Authenticated (Contributor+) Stored Cross-Site Scripting

The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.12.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inj...

Published
Apr 04, 2025
Patched Release
1.12.57
Affected Versions
Versions up to 1.12.20
Next Step
Update to 1.12.57 or newer if supported.
Plugin High Patched: Yes CVE-2024-12544
CVE-2024-12544: SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity <= 1.12.17 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion via SurveyJS_DeleteFile

The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to arbitrary file deletion due to a missing capability check on the callback function of the SurveyJS_DeleteFile class in all versions u...

Published
Feb 28, 2025
Patched Release
1.12.18
Affected Versions
Versions up to 1.12.17
Next Step
Update to 1.12.18 or newer if supported.
Plugin High Patched: Yes CVE-2024-50427
CVE-2024-50427: SurveyJS: Drag & Drop WordPress Form Builder <= 1.9.136 - Authenticated (Subscriber+) Arbitrary File Upload

The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.9.136. This makes it possible for...

Published
Oct 24, 2024
Patched Release
1.12.4
Affected Versions
Versions up to 1.9.136
Next Step
Update to 1.12.4 or newer if supported.