Impact
Improper Neutralization of Input During Web Page Generation (Cross‑site Scripting) allows attackers to store malicious code in the Advanced FAQ Manager plugin’s database. When the stored content is later rendered on the site, the code executes in users’ browsers, providing the attacker with a means to hijack sessions, deface pages, or inject additional malware.
Affected Systems
ThemeHigh Advanced FAQ Manager, versions from n/a through 1.5.2. WordPress sites that install this plugin without updating to a fixed release are vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.9, indicating moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. It is not listed in the CISA KEV catalog. Attackers can exploit this flaw by adding or editing FAQ entries containing unsanitized user input; the impact is confined to the browser of any visitor rendering the affected content. Educational or maintained environments that already use the latest plugin version are effectively protected.
OpenCVE Enrichment