PT-2026-26837 · WordPress · Surveyjs
Daniel Basta
·
Published
2026-03-21
·
Updated
2026-03-21
·
CVE-2026-2440
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SurveyJS plugin for WordPress versions through 2.5.3
Description
The software is susceptible to Stored Cross-Site Scripting through survey result submissions. Insufficient input sanitization and output escaping allow attackers to inject HTML-encoded payloads. The nonce required for submission is exposed on the public survey page, enabling unauthenticated attackers to submit malicious content. When an administrator views survey results, the injected payload is decoded and executed as HTML, resulting in stored XSS within the admin context.
Recommendations
Update the SurveyJS plugin to a version later than 2.5.3.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Surveyjs