PT-2026-84638 · WordPress · Faq Builder Ays
CVE-2026-81737
·
Published
2026-09-02
·
Updated
2026-09-02
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FAQ Builder AYS versions prior to 1.8.5
Description
Stored Cross-Site Scripting (XSS) occurs when the plugin fails to properly sanitize or escape content submitted by unauthenticated visitors. Although some escaping is applied, a subsequent decoding step reverses it before the content is stored and displayed on an admin area page. This allows malicious scripts to execute within the session of a logged-in administrator via the
ays get user information function.Recommendations
Update FAQ Builder AYS to version 1.8.5 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Faq Builder Ays