CVE-2024-11458: FAQ Builder AYS <= 1.7.1 - Reflected Cross-Site Scripting
The FAQ Builder AYS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'aysfaqtab' parameter in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11458?
CVE-2024-11458 is classified as a high-severity vulnerability due to its potential for exploitation via reflected cross-site scripting.
How do I fix CVE-2024-11458?
To remediate CVE-2024-11458, update the AYS FAQ Builder plugin to version 1.7.2 or later.
What versions of AYS FAQ Builder are affected by CVE-2024-11458?
All versions of the AYS FAQ Builder plugin up to and including 1.7.1 are vulnerable to CVE-2024-11458.
Can unauthenticated users exploit CVE-2024-11458?
Yes, unauthenticated attackers can exploit CVE-2024-11458 due to insufficient input sanitization in the plugin.
What type of vulnerability is CVE-2024-11458?
CVE-2024-11458 is a reflected cross-site scripting (XSS) vulnerability.