Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Maker survey-maker allows Stored XSS.This issue affects Survey Maker: from n/a through <= 5.1.3.5.
Published: 2025-02-04
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises when the Survey Maker plugin stores user‑supplied content without properly escaping HTML or JavaScript, allowing an attacker to embed malicious scripts that are later rendered when the survey page is viewed. Because the payload is written to the database and then injected into the web page, any visitor who loads the affected survey will have the script executed in their browser. The weakness is identified as CWE‑79, and if exploited it can lead to the transfer of session cookies, defacement of the page, or redirection to malicious sites. The potential damage is contingent on what the attacker can achieve through the injected script, and it is reasonable to infer that credentials or session data could be exfiltrated, and that the integrity of the site could be compromised.

Affected Systems

Any WordPress installation that includes the Ays Pro Survey Maker plugin with a version equal to or older than 5.1.3.5. The vulnerability covers all releases from the first component of the plugin through the identified upper bound, with no lower version constraint specified.

Risk and Exploitability

The CVSS score of 5.9 classifies the flaw as moderate risk, and the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need a victim to load a survey containing the malicious input, so user interaction is required. Because the injected scripts execute in the context of the viewer’s session, they can potentially steal credentials or deface the site, thereby impacting confidentiality and integrity.

Generated by OpenCVE AI on May 2, 2026 at 04:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to any Survey Maker plugin release newer than 5.1.3.5, preferably the latest stable version.
  • Implement a content‑security‑policy that disallows inline scripts and restricts script sources on survey‑related pages.
  • If upgrading is not immediately possible, restrict or sanitize any form fields that accept arbitrary input and enforce strict validation on both client and server sides to ensure only safe content is stored.

Generated by OpenCVE AI on May 2, 2026 at 04:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-2902 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Stored XSS. This issue affects Survey Maker: from n/a through 5.1.3.5.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Stored XSS. This issue affects Survey Maker: from n/a through 5.1.3.5. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Maker survey-maker allows Stored XSS.This issue affects Survey Maker: from n/a through <= 5.1.3.5.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}

cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00028}

epss

{'score': 0.00035}


Fri, 18 Apr 2025 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Ays-pro
Ays-pro survey Maker
CPEs cpe:2.3:a:ays-pro:survey_maker:*:*:*:*:*:wordpress:*:*
Vendors & Products Ays-pro
Ays-pro survey Maker

Tue, 04 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Feb 2025 14:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Stored XSS. This issue affects Survey Maker: from n/a through 5.1.3.5.
Title WordPress Survey Maker Plugin <= 5.1.3.5 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Ays-pro Survey Maker
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:03.839Z

Reserved: 2025-01-07T21:02:51.801Z

Link: CVE-2025-22664

cve-icon Vulnrichment

Updated: 2025-02-04T14:43:46.815Z

cve-icon NVD

Status : Modified

Published: 2025-02-04T15:15:21.003

Modified: 2026-04-23T15:23:21.370

Link: CVE-2025-22664

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T05:00:12Z

Weaknesses