CVE-2025-22664: WordPress Survey Maker Plugin <= 5.1.3.5 - Cross Site Scripting (XSS) vulnerability
Published Feb 4, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Maker survey-maker allows Stored XSS.This issue affects Survey Maker: from n/a through <= 5.1.3.5.
Affected Software
3 affected components
Survey Maker Survey Maker<=5.1.3.5
WordPress Survey Maker Plugin<=5.1.3.5
ays-pro Survey Maker Wordpress<5.1.3.6
Remediation
Information
Update the WordPress Survey Maker wordpress plugin to the latest available version (at least 5.1.3.6).
Event History
Feb 4, 2025
CVE Published
via MITRE·02:21 PM
Data Sourced
via MITRE·02:21 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-22664?
CVE-2025-22664 has a high severity rating due to its potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2025-22664?
To fix CVE-2025-22664, update Survey Maker to version 5.1.3.6 or later.
3
What software is affected by CVE-2025-22664?
CVE-2025-22664 affects Survey Maker versions up to and including 5.1.3.5, as well as the WordPress Survey Maker Plugin.
4
What type of vulnerability is CVE-2025-22664?
CVE-2025-22664 is classified as a stored cross-site scripting (XSS) vulnerability.
5
Can CVE-2025-22664 impact user data?
Yes, CVE-2025-22664 can potentially allow attackers to execute scripts that manipulate user data and session information.