Sleekplan – User Feedback, Roadmap & Changelog

Sleekplan – User Feedback, Roadmap & Changelog has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Sleekplan – User Feedback, Roadmap & Changelog has a vendor fix available, so running the current release closes it.

All of these findings were reported by Kévin Mosbahi (Mika). Sleekplan – User Feedback, Roadmap & Changelog is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Sleekplan – User Feedback, Roadmap & Changelog vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2025-23469

Sleekplan <= 0.2.0 - Reflected Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Sleekplan – User Feedback, Roadmap & Changelog banner
Latestv1.0.0

Sleekplan – User Feedback, Roadmap & Changelog

sleekplan

Author

sleekplan

5.0(2)
100/100
Last Updated
2026-07-27 (2mo ago)
Active Installs
10+
Downloads
9,031
Requires WP
5.0+
Requires PHP
7.0+
Tested up to
WP 7.0.4
Created
2020-06-18 (6y ago)

Sleekplan is an all-in-one customer feedback tool: collect and manage feedback, let users vote and discuss ideas, share a roadmap, keep a changelog, and measure satisfaction (CSAT/NPS) — all inside one widget that lives on your site. This plugin is the easiest way to add the Sleekplan widget to WordPress. It is intentionally small and does exactly two things: Load the widget — on your website, in your WP admin, or both. You choose. Single sign-on (optional) — automatically sign logged-in WordPress users in to the widget, so they can post and vote without a separate Sleekplan login. You control which profile data is shared: the email address is always included as the identifier; display name, user ID, and avatar are each optional. Privacy by design: the plugin stores its settings locally and makes no server-side connection to Sleekplan. Your WordPress installation and your Sleekplan account stay separate — the only resource loaded from Sleekplan is the widget script itself (client.sleekplan.com), in the visitor’s browser. With SSO enabled, a signed token containing the selected user data is handed to the widget. Setup takes about a minute: Create a product on Sleekplan — a free plan is available Copy your Product ID from the Sleekplan admin and paste it under WP Admin → Sleekplan Optional: enable SSO and paste your SSO key (Sleekplan admin → Settings → Single Sign-On) The widget itself (appearance, texts, modules, anonymous feedback, …) is configured in your Sleekplan admin. Here you can find our terms of use and privacy policies.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C