WordPress 插件 “The FAQ Builder AYS” 在 1.8.5 版本之前,未对未认证访客提交的内容进行过滤或转义,就在其存储并在管理员区域的页面中输出;而且该插件所应用的转义操作随后又被一个解码步骤所抵消,从而导致了存储型跨站脚本(Stored XSS)漏洞,该脚本将在已登录的管理员上下文中执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | FAQ Builder AYS | 1.6.3< 1.8.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | FAQ Builder AYS | 1.6.3 ~ 1.8.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-4357 | 10.0 CRITICAL | Embed HTML5 Game <= 1.3 - Unauthenticated Arbitrary File Upload |
| CVE-2026-77009 | 9.9 CRITICAL | WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console |
| CVE-2025-9314 | 9.8 CRITICAL | Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File Upload |
| CVE-2025-15485 | 8.2 HIGH | Auto x LINE <= 1.0.0 – Unauthenticated REST API Endpoints Call |
| CVE-2026-83547 | 6.8 MEDIUM | Xpro Elementor Addons 1.6.0 - 1.7.3 - Contributor+ Stored XSS via Multiple Widgets |
| CVE-2026-82884 | 6.8 MEDIUM | All in One SEO < 5.0.0.1 - Contributor+ Stored XSS via ai-assistant Block |
| CVE-2026-10821 | 6.6 MEDIUM | Yoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection to RCE |
| CVE-2026-2688 | 6.5 MEDIUM | CM HIPAA Forms < 3.2.0 - Unauthenticated Authorization Bypass |
| CVE-2024-3773 | 5.9 MEDIUM | LiveJournal Shortcode <= 1.1.1 - Contributor+ Stored XSS via Shortcode |
| CVE-2026-2811 | 5.4 MEDIUM | Ajaxify Comments < 3.2 - Unauthenticated HTTP Header Injection |
| CVE-2026-8151 | 5.4 MEDIUM | Simple Membership MailChimp Integration < 1.9.8 - API Key Update via CSRF |
| CVE-2025-15481 | 5.3 MEDIUM | Notification Bar for WordPress <= 1.1.8 – Unauthenticated Subscriber Data Disclosure |
| CVE-2026-17563 | 5.3 MEDIUM | WP User Frontend < 4.3.11 - Unauthenticated Post Creation via Subscription-Gated Form |
| CVE-2025-8945 | 5.3 MEDIUM | Wp Edit Password Protected < 1.3.5 - Protection Bypass via REST API |
| CVE-2025-15490 | 5.3 MEDIUM | Passster < 4.2.26 - Global Protection Bypass |
| CVE-2026-77793 | 5.3 MEDIUM | RegistrationMagic < 6.0.9.9 - Unauthenticated Payment Bypass via Omitted Price Field |
| CVE-2026-77794 | 5.3 MEDIUM | RegistrationMagic 6.0.0.0 - 6.0.9.8 - Unauthenticated Payment Bypass via Zero Quantity |
| CVE-2025-15489 | 5.3 MEDIUM | Passster < 4.2.24 - Password Protection Bypass |
| CVE-2026-83533 | 5.3 MEDIUM | WP Express Checkout < 2.4.9 - Unauthenticated Payment Bypass via wpec_process_payment |
| CVE-2026-78153 | 5.3 MEDIUM | Restrict User Access 2.6 - 2.8 - Unauthenticated Content Protection Bypass via REST API Ro |
Showing top 20 of 66 CVEs. View all on vendor page → →
No comments yet