XSS Vulnerability in Ultimate FAQ Plugin for WordPress by WebDevStudios
CVE-2020-7107
6.1MEDIUM
Summary
The Ultimate FAQ plugin for WordPress is susceptible to Cross-Site Scripting (XSS) due to insufficient input validation in the Display_FAQ function. Attackers can exploit this vulnerability by injecting malicious scripts into user-generated content displayed on WordPress sites via the Shortcodes/DisplayFAQs.php file. It is crucial for users of the plugin to update to version 1.8.30 or later to mitigate this security risk.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved