AYS Survey Maker
cpe:2.3:a:ays-pro:survey_maker:*:*:*:*:wordpress:*:*
- <= 5.1.3.3
A stored cross-site scripting vulnerability has been identified in the Survey Maker plugin for WordPress, affecting all versions through 5.1.3.3. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with administrator-level access to inject arbitrary web scripts into survey questions. This injected script executes when a user accesses the affected survey page. The vulnerability is present in multi-site installations where the 'unfiltered_html' capability has been disabled.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the survey.
To reproduce this vulnerability, an authenticated user with administrator privileges can navigate to the Survey Maker plugin's section for creating or editing surveys. Within a survey, the user can add a question and inject a script into the 'title' parameter of the question. Once the survey is saved, the injected script will execute when the survey page is accessed.
Users are advised to update the Survey Maker plugin to version 5.1.3.4 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.