CVE-2024-50426: WordPress Survey Maker plugin <= 5.0.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Maker survey-maker allows Stored XSS.This issue affects Survey Maker: from n/a through <= 5.0.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50426?
CVE-2024-50426 has a moderate severity level, as it allows stored cross-site scripting (XSS) vulnerabilities.
How do I fix CVE-2024-50426?
To fix CVE-2024-50426, update Survey Maker or the WordPress Survey Maker plugin to the latest version beyond 5.0.2.
What type of attack does CVE-2024-50426 involve?
CVE-2024-50426 involves stored XSS attacks, allowing attackers to inject malicious scripts into web pages.
Which versions of Survey Maker are affected by CVE-2024-50426?
CVE-2024-50426 affects all versions of Survey Maker from n/a up to and including 5.0.2.
Is there a workaround for CVE-2024-50426?
Currently, the best approach for CVE-2024-50426 is to update to a patched version, as no specific workarounds have been recommended.