{"error":0,"message":null,"data":{"name":"Ultimate FAQ Accordion Plugin","plugin":"ultimate-faqs","link":"https:\/\/wordpress.org\/plugins\/ultimate-faqs\/","latest":"1787235600","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"e0a198b92765c6598620a6870a2f519d5d8bb0a984e26035500890e7edbb7775","name":"Ultimate FAQ Accordion Plugin [ultimate-faqs] < 2.1.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24968","name":"CVE-2021-24968","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24968","description":"[en] The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ and FAQ questions","date":"2022-01-24"},{"id":"1f2dbab4bb70d013d47ccc9c97bcb2ec4c1499f4","name":"WordPress Ultimate FAQ plugin <= 2.1.1 - Arbitrary FAQ Creation vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ultimate-faqs\/vulnerability\/wordpress-ultimate-faq-plugin-2-1-1-arbitrary-faq-creation-vulnerability","description":"Arbitrary FAQ Creation vulnerability discovered by Krzysztof Zaj\u0105c in WordPress Ultimate FAQ plugin (versions <= 2.1.1).","date":"2021-12-27"},{"id":"f0a9e6cc-46cc-4ac2-927a-c006b8e8aa68","name":"Ultimate FAQ &lt; 2.1.2 - Subscriber+ Arbitrary FAQ Creation","link":"https:\/\/wpscan.com\/vulnerability\/f0a9e6cc-46cc-4ac2-927a-c006b8e8aa68","description":"The plugin does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ and FAQ questions","date":null},{"id":"1a8984b04f0bb6e89a9dfb42419f84ba73d40d84","name":"Ultimate FAQ <= 2.1.1 - Missing Authorization to Arbitrary FAQ Creation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ultimate-faqs\/ultimate-faq-211-missing-authorization-to-arbitrary-faq-creation","description":"The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ and FAQ questions","date":"2021-12-27"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:U\/C:N\/I:H\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"u","c":"n","i":"h","a":"n","score":"5.7","severity":"m","exploitable":"2.1","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:U\/C:N\/I:H\/A:N","score":"5.7","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"unchanged","c":"none","i":"high","a":"none","exploitable":"2.1","impact":"3.6"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."},{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}]}},{"uuid":"b8bfde80c52725945f8d23339ce9f911d4bab421a5482aa90792e3746d839213","name":"Ultimate FAQ Accordion Plugin [ultimate-faqs] < 1.8.30","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.30","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-7107","name":"CVE-2020-7107","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-7107","description":"[en] The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes\/DisplayFAQs.php.","date":"2020-01-16"},{"id":"5e1cefd5-5369-44bd-aef7-2a382c8d8e33","name":"Ultimate FAQ &lt; 1.8.30 - Unauthenticated Reflected XSS","link":"https:\/\/wpscan.com\/vulnerability\/5e1cefd5-5369-44bd-aef7-2a382c8d8e33","description":"The HTML code generated by the FAQ shortcode does not sanitise the Display_FAQ GET parameter, leading to an unauthenticated reflected Cross-Site Scripting issue on pages where such shortcode is used.","date":null},{"id":"9919579a6dfe648e1f8e02a9fd87909b1cbfe8ca","name":"Ultimate FAQ <= 1.8.29 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ultimate-faqs\/ultimate-faq-1829-reflected-cross-site-scripting","description":"The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes\/DisplayFAQs.php.","date":"2020-01-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"692e2ec5e8390391d25c3a4dd4ae7b7b1141f4112b459dc363639de2af58f197","name":"Ultimate FAQ Accordion Plugin [ultimate-faqs] < 1.8.25","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.25","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-17233","name":"CVE-2019-17233","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-17233","description":"[en] Functions\/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.","date":"2019-10-07"},{"id":"4fc5b78019ce0afbd34b90a2d74b5e18d99d87b4","name":"Ultimate FAQ <= 1.8.24 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ultimate-faqs\/ultimate-faq-1824-cross-site-scripting","description":"Functions\/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.","date":"2019-09-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"0faec6ef03e459cff60b647fe2606a088d134f03f0868367cd5f2192dc5adc68","name":"Ultimate FAQ Accordion Plugin [ultimate-faqs] < 1.8.25","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.25","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-17232","name":"CVE-2019-17232","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-17232","description":"[en] Functions\/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.","date":"2019-10-07"},{"id":"b32b5226-d845-4262-8d7a-3aba74677336","name":"Ultimate FAQ &lt; 1.8.25 - Unauthenticated Options Import\/Export","link":"https:\/\/wpscan.com\/vulnerability\/b32b5226-d845-4262-8d7a-3aba74677336","description":"The Ultimate FAQ &ndash; WordPress Q&amp;A Plugin WordPress plugin was affected by an Unauthenticated Options Import\/Export security vulnerability.","date":null},{"id":"0851deb32a41d7a98de0c60c8d4714c349793b0f","name":"Ultimate FAQ <= 1.8.24 - Unauthenticated Options Import\/Export","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ultimate-faqs\/ultimate-faq-1824-unauthenticated-options-importexport","description":"Functions\/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.","date":"2019-09-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"h","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"high","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-306","name":"Missing Authentication for Critical Function","description":"The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources."}]}},{"uuid":"1e557a2d887425f30b1b0874e6efb7139c7327147164c5667aa864262314a328","name":"Ultimate FAQ Accordion Plugin [ultimate-faqs] < 1.8.22","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.22","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-15643","name":"CVE-2019-15643","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-15643","description":"[en] The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.","date":"2019-08-27"},{"id":"6aa029ea-fb04-4bf5-b771-68e463ea8ec7","name":"Ultimate Faqs &lt; 1.8.22 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/6aa029ea-fb04-4bf5-b771-68e463ea8ec7","description":"The Ultimate FAQ &ndash; WordPress Q&amp;A Plugin WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null},{"id":"d5920e97b599cfa46c74cdc0a9597d503b651ffb","name":"Ultimate Faqs <= 1.8.21 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ultimate-faqs\/ultimate-faqs-1821-cross-site-scripting","description":"The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.","date":"2019-05-08"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"edb864468110d196c0f31ca75aebf586abee5d76847bf41bc5a109eab57bc7cb","name":"Ultimate FAQ Accordion Plugin [ultimate-faqs] < 1.8.30","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.30","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"17825b9e89387356871548c7c54b51d4e87c5671","name":"WordPress Ultimate FAQ plugin <= 1.8.29 - Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ultimate-faqs\/vulnerability\/wordpress-ultimate-faq-plugin-1-8-29-unauthenticated-reflected-cross-site-scripting-xss-vulnerability","description":"Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found in WordPress Ultimate FAQ plugin (versions <= 1.8.29).","date":"2020-01-07"}],"impact":[]},{"uuid":"41b4cbc7d33472bddb965151c4533d57ba92f2257422e9a7cd0651fb14abe81e","name":"Ultimate FAQ Accordion Plugin [ultimate-faqs] < 1.8.25","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.25","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5e0e5265f80db503d6028dc9541c51fde13428e9","name":"WordPress Ultimate FAQ plugin <= 1.8.24 - Unauthenticated Options Import\/Export vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ultimate-faqs\/vulnerability\/wordpress-ultimate-faq-plugin-1-8-24-unauthenticated-options-import-export-vulnerability","description":"Unauthenticated Options Import\/Export vulnerability found by Jerome Bruandet in WordPress Ultimate FAQ plugin (versions <= 1.8.24).","date":"2019-09-23"}],"impact":[]},{"uuid":"f501e1e3b6d3e74867eeae085d6d6b512205b7f1f42568d03e9ab504abb31f77","name":"Ultimate FAQ Accordion Plugin [ultimate-faqs] < 2.4.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-67590","name":"CVE-2025-67590","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-67590","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate FAQ ultimate-faqs allows Cross Site Request Forgery.This issue affects Ultimate FAQ: from n\/a through <= 2.4.3.","date":"2025-12-09"},{"id":"9db7beb735eac23f18b8398bb7b58b7c2ce8ee40","name":"Ultimate FAQ <= 2.4.3 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ultimate-faqs\/ultimate-faq-243-cross-site-request-forgery","description":"The Ultimate FAQ Accordion Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2025-11-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2f2a587c3f0eb5e0d06681e3e7f4171b306017e845169a783591b30712ca23ff","name":"Ultimate FAQ Accordion Plugin [ultimate-faqs] < 2.4.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-4336","name":"Ultimate FAQ Accordion Plugin <= 2.4.7 - Authenticated (Author+) Stored Cross-Site Scripting via FAQ Content","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-4336","description":"The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all versions up to, and including, 2.4.7. This is due to the plugin calling html_entity_decode() on post_content during rendering in the set_display_variables() function (View.FAQ.class.php, line 746), which converts HTML entity-encoded payloads back into executable HTML, combined with insufficient output escaping in the faq-answer.php template where the decoded content is echoed without wp_kses_post() or any other sanitization. The ufaq custom post type is registered with 'show_in_rest' => true and defaults to 'post' capability_type, allowing Author-level users to create and publish FAQs via the REST API. An Author can submit entity-encoded malicious HTML (e.g., &lt;img src=x onerror=alert()&gt;) which bypasses WordPress's kses sanitization at save time (since kses sees entities as plain text, not tags), but is then decoded back into executable HTML by html_entity_decode() at render time. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in FAQ pages that will execute whenever a user accesses an injected FAQ, either directly or via the [ultimate-faqs] shortcode.","date":"0000-00-00"},{"id":"5bac7fd1b2c6e1193fb87856e6d078ea9afd2b24","name":"WordPress Ultimate FAQ Plugin <= 2.4.7 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ultimate-faqs\/vulnerability\/wordpress-ultimate-faq-accordion-plugin-plugin-2-4-7-authenticated-author-stored-cross-site-scripting-via-faq-content-vulnerability","description":"<p>WordPress Ultimate FAQ Plugin <= 2.4.7 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Ultimate FAQ<\/p><p>Fixed in version 2.4.8 <\/p><p>Affected Version <= 2.4.7<\/p><p>CVE: CVE-2026-4336<\/p>","date":"2026-04-09"},{"id":"2f91a3cd02e6ca67c401aa9e8cd4470fc0d27af3","name":"Ultimate FAQ Accordion Plugin <= 2.4.7 - Authenticated (Author+) Stored Cross-Site Scripting via FAQ Content","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ultimate-faqs\/ultimate-faq-accordion-plugin-247-authenticated-author-stored-cross-site-scripting-via-faq-content","description":"The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all versions up to, and including, 2.4.7. This is due to the plugin calling html_entity_decode() on post_content during rendering in the set_display_variables() function (View.FAQ.class.php, line 746), which converts HTML entity-encoded payloads back into executable HTML, combined with insufficient output escaping in the faq-answer.php template where the decoded content is echoed without wp_kses_post() or any other sanitization. The ufaq custom post type is registered with 'show_in_rest' => true and defaults to 'post' capability_type, allowing Author-level users to create and publish FAQs via the REST API. An Author can submit entity-encoded malicious HTML (e.g., &lt;img src=x onerror=alert()&gt;) which bypasses WordPress's kses sanitization at save time (since kses sees entities as plain text, not tags), but is then decoded back into executable HTML by html_entity_decode() at render time. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in FAQ pages that will execute whenever a user accesses an injected FAQ, either directly or via the [ultimate-faqs] shortcode.","date":"2026-04-08"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1776417364"}