What the vulnerability does
01Description
Missing Authorization vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Feedback: from n/a through <= 1.10.1.
Explanation of Vulnerability in Simple Terms
02Summary
User Feedback through version 1.10.1 fails to properly check user permissions before allowing access to feedback data. A logged-in user with low privileges can read feedback submitted by other users, including potentially sensitive information. The vulnerability requires an active user account but no special interaction from the victim.
What an attacker can do
03Attacker Capabilities
Read feedback data submitted by other users on the site.
Potential impact on your site
04Site Impact
User feedback intended to be private may be exposed to other registered users.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account and network access to the site.
Key dates
06Disclosure timeline
April 8, 2026
CVE published
April 29, 2026
Record updated