Impact
The SurveyJS plugin for WordPress is vulnerable to Stored Cross‑Site Scripting due to insufficient input sanitisation and output escaping of the ‘id’ parameter, a weakness that aligns with CWE‑79. The flaw allows an authenticated user with Contributor‑level access or higher to inject arbitrary JavaScript into a survey page. When any user subsequently views the affected page, the injected script executes under their browser context, potentially compromising their session, defacing content, or facilitating further attacks.
Affected Systems
The affected software is SurveyJS, a Drag & Drop Form Builder developed by devsoftbaltic. All versions up to and including 1.12.32 are impacted. No other vendors, products or versions are listed as affected.
Risk and Exploitability
The CVSS score of 6.4 classifies the vulnerability as a moderate impact issue. The EPSS score of < 1% indicates a very low probability of exploitation at present, and it is not listed in the CISA KEV catalog. Attackers must be authenticated with Contributor level or higher to exploit the flaw. Once injected, the malicious script runs for any user who accesses the survey page, so the scope can be system‑wide if a survey is broadly shared.
OpenCVE Enrichment
EUVD