PT-2026-84638 · WordPress · Faq Builder Ays

CVE-2026-81737

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FAQ Builder AYS versions prior to 1.8.5
Description Stored Cross-Site Scripting (XSS) occurs when the plugin fails to properly sanitize or escape content submitted by unauthenticated visitors. Although some escaping is applied, a subsequent decoding step reverses it before the content is stored and displayed on an admin area page. This allows malicious scripts to execute within the session of a logged-in administrator via the ays get user information function.
Recommendations Update FAQ Builder AYS to version 1.8.5 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81737

Affected Products

Faq Builder Ays