PT-2022-9722 · WordPress · Survey Maker
Ngo Van
+1
·
Published
2022-02-21
·
Updated
2022-02-28
·
CVE-2021-26256
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Survey Maker WordPress plugin versions <= 2.0.6
Description
The issue is related to an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This type of vulnerability allows attackers to inject malicious scripts into content from otherwise trusted websites, which are then executed by users' browsers.
Recommendations
For Survey Maker WordPress plugin versions <= 2.0.6, update to a version greater than 2.0.6 to resolve the issue.
As a temporary workaround, consider restricting access to the plugin's functionality to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Survey Maker