Cross-site Scripting Vulnerability in Ays Pro Survey Maker Product by WordPress
CVE-2025-48095

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 October 2025

What is CVE-2025-48095?

A stored Cross-site Scripting (XSS) vulnerability exists in the Ays Pro Survey Maker plugin for WordPress, allowing attackers to inject malicious scripts into web pages viewed by other users. This vulnerability stems from improper input sanitization during web page generation, which can lead to unauthorized actions or data exposure when an unsuspecting user interacts with the compromised survey. It is crucial for web administrators to update to the latest version or apply necessary patches to mitigate the risks associated with this vulnerability.

Affected Version(s)

Survey Maker <= n/a

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kim YunJi (Patchstack Alliance)
.