Impact
The Survey Maker plugin for WordPress, up to and including version 5.2.2.5, contains an unauthenticated cross‑site scripting flaw. When a visitor loads a survey page that incorporates a malicious payload, the script executes in the visitor’s browser. The flaw arises from an input‑validation oversight, identified as CWE‑79.
Affected Systems
WordPress installations that have the Survey Maker (Ays Pro:Survey) plugin installed at version 5.2.2.5 or earlier are affected; no other vendors or products are implicated.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate severity. Because authentication is not required, any visitor who can view a survey can trigger the injection. The EPSS score is low (<1 %), suggesting that widespread exploitation is not currently likely, and the flaw is not listed in the CISA KEV catalog. Nonetheless, client‑side script execution poses a serious security risk and should be remediated promptly.
OpenCVE Enrichment