CVE-2017-1002021: Surveys Project Surveys

Critical severity, CVSS 9.8. EPSS: 3.6% chance of exploitation in the next 30 days.

Vulnerability in wordpress plugin surveys v1.01.8, The code in individual_responses.php does not sanitize the survey_id variable before placing it inside of an SQL query.

Affected products

Published 2017-09-14. Last modified 2026-06-17.