SureFeedback Client Site
SureFeedback Client Site has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (50%). Other recurring categories include Missing Authorization.
Every one of the 2 issues recorded for SureFeedback Client Site has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. SureFeedback Client Site is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2026-80433SureFeedback Client Site <= 1.2.12 - Authenticated (Subscriber+) Information Exposure
Read the full analysisVulnerability Records

SureFeedback Client Site
Author
Brainstorm Force
This is the Child plugin for SureFeedback The SureFeedback plugin lets you collect sticky note-style feedback on page designs and web projects. It’s so easy to use. Clients can select specific areas of your design, point, click, and type constructive comments on top of your mockups and site designs. Using SureFeedback, the client can show as well as tell, providing targeted feedback for a more efficient workflow. SureFeedback is a self-hosted client feedback system that allows you to get feedback on an endless amount of client sites from one central dashboard. The SureFeedback Client Site plugin is used to securely sync multiple WordPress client identities with your SureFeedback parent site. All you need to do is install the plugin on the site you want feedback on and it’s ready to go. Features include: Connect and sync your client’s identities with your SureFeedback projects. No login or registration is required if your client is logged into their own site. Choose which roles you want to allow for commenting. Allow non-users (guests) to leave comments. Optionally enable commenting on the WordPress admin. White label support
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C