Impact
The vulnerability is an improper neutralization of input during web page generation, classified as a stored cross‑site scripting flaw. An attacker can embed malicious scripts into survey data that are rendered directly on the site, leading to script execution in any browser that views the affected survey page. This can be used for session hijacking, defacement, or other client‑side attacks.
Affected Systems
The flaw affects the Ays Pro Survey Maker plugin for WordPress, versions from the earliest release through 5.1.8.8. Sites running any of these versions with public access to survey creation or viewing are vulnerable.
Risk and Exploitability
The CVSS score of 5.9 denotes moderate severity, while an EPSS of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the presence of the vulnerable plugin and the ability to introduce script‑containing survey data; once injected, the payload runs automatically for all users who view the survey, making the attack condition relatively low‑barrier. Given the moderate CVSS and low EPSS, the immediate risk is moderate but could be higher on high‑traffic or highly exposed sites.
OpenCVE Enrichment