CVE-2019-17233: XSS
Functions/EWDUFAQImport.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-17233?
CVE-2019-17233 is a vulnerability in the ultimate-faqs plugin for WordPress that allows HTML content injection.
What is the severity of CVE-2019-17233?
The severity of CVE-2019-17233 is medium.
How does CVE-2019-17233 affect the ultimate-faqs plugin?
CVE-2019-17233 affects the ultimate-faqs plugin through version 1.8.24 of the plugin for WordPress.
How can I fix CVE-2019-17233?
To fix CVE-2019-17233, you should update the ultimate-faqs plugin to a version higher than 1.8.24.
Where can I find more information about CVE-2019-17233?
You can find more information about CVE-2019-17233 on the following references: [link1](https://blog.nintechnet.com/unauthenticated-options-import-vulnerability-in-wordpress-ultimate-faq-plugin/), [link2](https://wordpress.org/plugins/ultimate-faqs/#developers), [link3](https://wpvulndb.com/vulnerabilities/9883).