PT-2026-26837 · WordPress · Surveyjs
Daniel Basta
·
Publicado
2026-03-21
·
Atualizado
2026-03-21
·
CVE-2026-2440
CVSS v3.1
7.2
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SurveyJS plugin for WordPress versions through 2.5.3
Description
The software is susceptible to Stored Cross-Site Scripting through survey result submissions. Insufficient input sanitization and output escaping allow attackers to inject HTML-encoded payloads. The nonce required for submission is exposed on the public survey page, enabling unauthenticated attackers to submit malicious content. When an administrator views survey results, the injected payload is decoded and executed as HTML, resulting in stored XSS within the admin context.
Recommendations
Update the SurveyJS plugin to a version later than 2.5.3.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Surveyjs