PT-2026-26837 · WordPress · Surveyjs

Daniel Basta

·

Publicado

2026-03-21

·

Atualizado

2026-03-21

·

CVE-2026-2440

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SurveyJS plugin for WordPress versions through 2.5.3
Description The software is susceptible to Stored Cross-Site Scripting through survey result submissions. Insufficient input sanitization and output escaping allow attackers to inject HTML-encoded payloads. The nonce required for submission is exposed on the public survey page, enabling unauthenticated attackers to submit malicious content. When an administrator views survey results, the injected payload is decoded and executed as HTML, resulting in stored XSS within the admin context.
Recommendations Update the SurveyJS plugin to a version later than 2.5.3.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-2440

Produtos afetados

Surveyjs