Impact
The vulnerability is a classic Cross‑Site Scripting flaw that arises when contributors submit content through the Ultimate FAQ plugin; unfiltered data is injected into FAQ pages, allowing an attacker to run arbitrary JavaScript in the browsers of users that view the affected FAQ items, potentially leading to session hijacking, data theft, or defacement.
Affected Systems
The flaw affects WordPress sites running Rustaurius Ultimate FAQ plugin versions 2.4.14 and earlier, and the issue was identified by the CNA and unpublished to the CISA KEV catalog; upgrading to version 2.5.0 or later removes the vulnerability.
Risk and Exploitability
The CVSS base score of 6.5 denotes moderate risk, and with no EPSS data the precise exploitation probability is unclear, but because the attack requires a contributor role or the ability to add FAQ entries, the threat surface is largely limited to sites that permit such contributions; the vulnerability is not present in the KEV catalog, indicating that widespread exploitation has not yet been observed.
OpenCVE Enrichment