Impact
The Survey Maker plugin for WordPress, up to and including version 5.2.2.5, contains an unauthenticated cross‑site scripting flaw that permits the injection of arbitrary JavaScript into survey pages. When a visitor loads a survey page that includes a malicious payload, the script runs in the victim’s browser. The flaw originates from an input validation oversight (CWE‑79).
Affected Systems
WordPress installations that have the Survey Maker (Ays Pro:Survey) plugin installed at version 5.2.2.5 or earlier are affected; no other vendors or products are implicated.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity. Because authentication is not required, any visitor who can view a survey can trigger the injection. The EPSS score is low (<1 %), suggesting that widespread exploitation is not currently likely, and the flaw is not listed in the CISA KEV catalog. Nonetheless, client‑side script execution poses a serious security risk and should be remediated promptly.
OpenCVE Enrichment