CVE-2026-39476

WordPress User Feedback plugin <= 1.10.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Feedback: from n/a through <= 1.10.1.


We have discovered 1,670 live websites that are affected by CVE-2026-39476.

Run a Free Instant Scan




Affected Software

Product  Userfeedback Lite
Category Wordpress Plugins
Vulnerable Domains1,670 live websites (86% of Userfeedback Lite install base)
Vulnerable Versions
  • from 0 through 1.10.1
Vulnerable Versions Count20 versions ( 91% of all versions)



Details

  • Published - Apr 8, 2026
  • Updated - Apr 29, 2026

Credits

  • Trương Hữu Phúc (truonghuuphuc) | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-39476
United States592 websites



Germany123 websites
France91 websites
GB75 websites
Italy74 websites
Japan72 websites
Cyprus53 websites
Brazil43 websites
Spain35 websites
South Africa33 websites

Website Distribution by TLD

Number of websites using CVE-2026-39476
.com863 websites
.org87 websites
.net59 websites
.it45 websites
.com.br39 websites
.de36 websites
.co.uk36 websites
.fr34 websites
.nl33 websites
.pl24 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-39476

Top websites that are affected by CVE-2026-39476. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******************.com Spain***,***
*****.org United States***,***
*****.org Germany***,***
**********.com United States***,***
********.***.do Dominican Republic***,***
*****************.com GB***,***
************.org United States***,***
*************.com Japan***,***
*********.org Canada***,***
*************.org Canada***,***
See full domain list

FAQ

A total of 1,670 websites have been identified as vulnerable to CVE-2026-39476, based on global website indexing conducted by WebTechSurvey.
The Userfeedback Lite is affected by the CVE-2026-39476 vulnerability.
Userfeedback Lite versions up to and including 1.10.1 are vulnerable to CVE-2026-39476.