Impact
The vulnerability is an unauthenticated XSS flaw present in the WordPress Survey Maker plugin versions up to 5.2.3.3. An attacker can inject malicious scripts that will execute in the browser of any user who views a page containing the affected survey. This can lead to defacement, theft of session tokens, or execution of arbitrary client‑side code, compromising confidentiality and integrity of the site’s users.
Affected Systems
The flaw affects installations of the Survey Maker plugin for WordPress supplied by Ays Pro. Versions 5.2.3.3 and older are vulnerable; the fix begins at version 5.2.3.4.
Risk and Exploitability
The CVSS score of 7.1 places the vulnerability in the high severity range. EPSS data is unavailable, and it is not listed in the CISA KEV catalog, indicating no known exploitation yet. However, because the XSS is unauthenticated and can be triggered by any visitor, attackers could use it without needing special privileges, making it a likely vector for phishing, session hijacking or malware delivery.
OpenCVE Enrichment