WordPress FAQ Builder AYS Cross-Site Scripting Vulnerability
Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in the WordPress FAQ Builder AYS plugin, specifically in versions through 1.8.2. This vulnerability arises from improper input neutralization during web page generation, allowing for the injection of malicious scripts. Exploitation of this issue is facilitated by incorrectly configured access control security levels.
Impact
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed when users visit the affected site. This could be used to inject redirects, advertisements, or other HTML payloads.
Remediation
Users of the WordPress FAQ Builder AYS plugin should update to version 1.8.3 or later. Patchstack users can enable auto-update for vulnerable plugins.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
