Impact
The FAQ Builder AYS plugin contains an instance of improper neutralization of input during web page generation, allowing an attacker to store malicious payloads that execute when a page is rendered. This stored XSS vulnerability, identified as CWE‑79, can enable an attacker to steal user credentials, deface the site, or redirect visitors to malicious sites. The plugin version addressed by the advisory is any release up to and including 1.7.3.
Affected Systems
Ays Pro: FAQ Builder AYS, affecting all deployments of the plugin from the initial release through version 1.7.3.
Risk and Exploitability
The CVSS base score of 5.9 indicates moderate severity. The EPSS score, below 1%, suggests the likelihood of exploitation is very low at present, and the vulnerability is not catalogued in CISA’s known exploited vulnerabilities list. The likely attack vector is via the plugin’s content input interface, reachable by a remote attacker with sufficient privileges or by exploiting a local user who inputs malicious content. The impact is limited to the integrity and authenticity of the site’s content rather than system compromise.
OpenCVE Enrichment
EUVD