SecAlerts
ays logo

ays

Security Risk Profile

30
/100
low

Security Risk Score

Comprehensive risk assessment based on 20 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 27, 2024 to present

20
Total CVEs
9
Critical+High
0
Exploited
4
Unpatched

Threat Assessment

Avg CVSS
6.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
4
Critical/High
Risk Level
30/100
low

Severity Distribution

Critical
2
High
7
Medium
11
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
7

Age Distribution

Common Weaknesses (CWE)

1
XSS
7
2
CSRF
3
3
Infoleak
1
4
SSRF
1
5
Race Condition
1

Most Affected Products

1. AYS AI ChatBot with ChatGPT and Content Generator4
2. Ays Pro Quiz Maker3
3. ays-pro Quiz Maker Wordpress3
4. Ays Quiz Maker2
5. Ays Image Slider by Ays2

Recent Vulnerabilities

See more →
CVE-2026-8995
CVSS 4.3EPSS 0%medium

Poll Maker by AYS <= 6.3.7 - Authenticated (Subscriber+) Sensitive Information Exposure in 'ays_poll_get_user_information' AJAX Action

5/29/2026🔧 No Patch
CVE-2026-6817
CVSS 5.8EPSS 0%medium

Quiz Maker by AYS <= 6.7.1.29 - Unauthenticated Stored Cross-Site Scripting via 'rate_reason'

5/2/2026🔧 No Patch
CVE-2026-32494
CVSS 7.1high

WordPress Image Slider by Ays plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability

3/25/2026🔧 No Patch
CVE-2026-25346
CVSS 7.1high

WordPress FAQ Builder AYS plugin <= 1.8.2 - Cross Site Scripting (XSS) vulnerability

3/25/2026🔧 No Patch
CVE-2026-32402
CVSS 5.3EPSS 0%medium

WordPress Image Slider by Ays plugin <= 2.7.1 - Broken Access Control vulnerability

3/13/2026🔧 No Patch
CVE-2026-25338
CVSS 5.3EPSS 0%medium

WordPress AI ChatBot with ChatGPT and Content Generator by AYS plugin <= 2.7.4 - Broken Access Control vulnerability

2/19/2026🔧 No Patch
CVE-2025-13685
CVSS 4.3medium

Photo Gallery by Ays <= 6.4.8 - Cross-Site Request Forgery to Bulk Actions

12/2/2025🔧 No Patch
CVE-2025-13381
CVSS 5.3medium

AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.0 - Missing Authorization to Unauthenticated Media File Uploads

11/27/2025🔧 No Patch
CVE-2025-13378
CVSS 6.5medium

AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.0 - Unauthenticated Server-Side Request Forgery via 'pinecone_url' Parameter

11/27/2025🔧 No Patch
CVE-2025-62039
CVSS 7.5high

WordPress AI ChatBot with ChatGPT and Content Generator by AYS plugin <= 2.6.6 - Sensitive Data Exposure vulnerability

11/6/2025🔧 No Patch

Monitor ays in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.