CVE-2017-1002020: Surveys Project Surveys

Critical severity, CVSS 9.8. EPSS: 3.6% chance of exploitation in the next 30 days.

Vulnerability in wordpress plugin surveys v1.01.8, The code in survey_form.php does not sanitize the action variable before placing it inside of an SQL query.

Affected products

Published 2017-09-14. Last modified 2026-06-17.