CVE-2025-48098: WordPress Survey Maker plugin <= 5.1.8.8 - Cross Site Scripting (XSS) vulnerability
Published Oct 22, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Maker survey-maker allows Stored XSS.This issue affects Survey Maker: from n/a through <= 5.1.8.8.
Affected Software
2 affected components
Ays Pro Survey Maker<=5.1.8.8
WordPress Survey Maker Plugin<=5.1.8.8
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-48098?
CVE-2025-48098 is classified as a Stored XSS vulnerability affecting specific versions of the Ays Pro Survey Maker.
2
How do I fix CVE-2025-48098?
To fix CVE-2025-48098, update the Ays Pro Survey Maker to a version newer than 5.1.8.8.
3
Which versions of Ays Pro Survey Maker are affected by CVE-2025-48098?
CVE-2025-48098 affects Ays Pro Survey Maker versions up to and including 5.1.8.8.
4
What is Stored XSS in the context of CVE-2025-48098?
Stored XSS refers to an attack where malicious scripts are stored on a server and executed in users' browsers.
5
Should I be concerned about CVE-2025-48098 on my website?
Yes, if you are using an affected version of Ays Pro Survey Maker, you should be concerned about potential XSS attacks.