Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Ays Pro — Vulnerabilities & Security Advisories 57

Browse all 57 CVE security advisories affecting Ays Pro. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Ays Pro functions as an automated testing platform designed to streamline software quality assurance and deployment workflows. Its architecture, which integrates with various CI/CD pipelines, has historically exposed it to significant security risks, resulting in fifty-three recorded Common Vulnerabilities and Exposures. The most prevalent vulnerability classes affecting the software include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and privilege escalation flaws, often stemming from insufficient input validation and improper access controls within its administrative interfaces. These defects have allowed attackers to potentially gain unauthorized system access or manipulate application behavior. While the platform aims to enhance development efficiency, its complex integration points have created attack vectors that require rigorous patch management. Recent security audits highlight the necessity for strict configuration hardening to mitigate these inherent risks associated with its automated execution capabilities.

CVE ID Title CVSS Severity Published
CVE-2025-24577 WordPress Poll Maker plugin <= 5.5.0 - Broken Access Control vulnerability — Poll Maker CWE-862 6.5 Medium 2025-04-17
CVE-2025-27285 WordPress Easy Form by AYS Plugin <= 2.6.9 - Reflected Cross Site Scripting (XSS) vulnerability — Easy Form CWE-79 7.1 High 2025-04-17
CVE-2025-32275 WordPress Survey Maker plugin <= 5.1.6.3 - Bypass vulnerability — Survey Maker CWE-290 4.3 Medium 2025-04-10
CVE-2025-32133 WordPress Secure Copy Content Protection and Content Locking plugin <= 4.5.5 - Cross Site Scripting (XSS) vulnerability — Secure Copy Content Protection and Content Locking CWE-79 5.9 Medium 2025-04-04
CVE-2025-30905 WordPress Secure Copy Content Protection and Content Locking plugin <= 4.4.3 - Cross Site Scripting (XSS) vulnerability — Secure Copy Content Protection and Content Locking CWE-79 7.1 High 2025-04-01
CVE-2025-30774 WordPress Quiz Maker plugin <= 6.6.8.7 - SQL Injection vulnerability — Quiz Maker CWE-89 8.2 High 2025-04-01
CVE-2025-30904 WordPress Chartify plugin <= 3.1.7 - Cross Site Scripting (XSS) vulnerability — Chartify CWE-79 5.9 Medium 2025-03-27
CVE-2025-26971 WordPress Poll Maker <= 5.6.5 - SQL Injection vulnerability — Poll Maker CWE-89 7.6 High 2025-02-25
CVE-2025-22664 WordPress Survey Maker Plugin <= 5.1.3.5 - Cross Site Scripting (XSS) vulnerability — Survey Maker CWE-79 5.9 Medium 2025-02-04
CVE-2025-24722 WordPress FAQ Builder AYS Plugin <= 1.7.3 - Cross Site Scripting (XSS) vulnerability — FAQ Builder AYS CWE-79 5.9 Medium 2025-01-24
CVE-2024-56277 WordPress Poll Maker Plugin < 5.5.5 - HTML Injection vulnerability — Poll Maker CWE-116 5.3 Medium 2025-01-21
CVE-2024-56295 WordPress Poll Maker plugin <= 5.5.6 - Broken Access Control vulnerability — Poll Maker CWE-862 6.5 Medium 2025-01-15
CVE-2023-45766 WordPress Poll Maker plugin <= 4.7.1 - Broken Access Control vulnerability — Poll Maker CWE-862 5.3 Medium 2025-01-02
CVE-2023-50904 WordPress Poll Maker plugin <= 4.8.0 - Broken Access Control vulnerability — Poll Maker CWE-862 5.3 Medium 2024-12-09
CVE-2024-50426 WordPress Survey Maker plugin <= 5.0.2 - Cross Site Scripting (XSS) vulnerability — Survey Maker CWE-79 5.9 Medium 2024-10-29
CVE-2024-47306 WordPress Secure Copy Content Protection and Content Locking plugin <= 4.2.3 - Cross Site Scripting (XSS) vulnerability — Secure Copy Content Protection and Content Locking CWE-79 7.1 High 2024-10-06
CVE-2024-47347 WordPress Chartify plugin <= 2.7.6 - Reflected Cross Site Scripting (XSS) vulnerability — Chartify CWE-79 7.1 High 2024-10-06
CVE-2021-24484 Secure Copy Content Protection and Content Locking < 2.6.7 - Authenticated Blind SQL Injections — Secure Copy Content Protection and Content Locking CWE-89 7.2 - 2021-08-02
CVE-2021-24483 Poll Maker < 3.2.1 - Authenticated Blind SQL Injections — Poll Maker CWE-89 7.2 - 2021-08-02
CVE-2021-24463 Image Slider by Ays - Responsive Slider and Carousel < 2.5.0 - Authenticated Blind SQL Injection — Image Slider by Ays- Responsive Slider and Carousel CWE-89 8.8 - 2021-08-02
CVE-2021-24462 Photo Gallery by Ays - Responsive Image Gallery < 4.4.4 - Authenticated Blind SQL Injections — Photo Gallery by Ays – Responsive Image Gallery CWE-89 8.8 - 2021-08-02
CVE-2021-24461 FAQ Builder < 1.3.6 - Authenticated Blind SQL Injections — FAQ Builder AYS CWE-89 8.8 - 2021-08-02
CVE-2021-24460 Popup Like box - Page Plugin < 3.5.3 - Authenticated Blind SQL Injections — Popup Like box – Page Plugin CWE-89 8.8 - 2021-08-02
CVE-2021-24459 Survey Maker < 1.5.6 - Authenticated Blind SQL Injections — Survey Maker CWE-89 8.8 - 2021-08-02
CVE-2021-24458 Popup box < 2.3.4 - Authenticated Blind SQL Injections — Popup box CWE-89 8.8 - 2021-08-02
CVE-2021-24457 Portfolio Responsive Gallery < 1.1.8 - Authenticated Blind SQL Injections — Portfolio Responsive Gallery CWE-89 8.8 - 2021-08-02
CVE-2021-24456 Quiz Maker < 6.2.0.9 - Multiple Authenticated Blind SQL Injections — Quiz Maker CWE-89 7.2 - 2021-08-02

This page lists every published CVE security advisory associated with Ays Pro. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.