XSS Vulnerability in Ultimate FAQ Plugin for WordPress by WebDevStudios
CVE-2020-7107
6.1MEDIUM
What is CVE-2020-7107?
The Ultimate FAQ plugin for WordPress is susceptible to Cross-Site Scripting (XSS) due to insufficient input validation in the Display_FAQ function. Attackers can exploit this vulnerability by injecting malicious scripts into user-generated content displayed on WordPress sites via the Shortcodes/DisplayFAQs.php file. It is crucial for users of the plugin to update to version 1.8.30 or later to mitigate this security risk.