Vulnerabilities > AYS PRO

DATE CVE VULNERABILITY TITLE RISK
2023-08-23 CVE-2023-32498 Cross-site Scripting vulnerability in Ays-Pro Easy Form
Auth.
network
low complexity
ays-pro CWE-79
4.8
2023-08-18 CVE-2023-32107 Cross-site Scripting vulnerability in Ays-Pro Photo Gallery
Unauth.
network
low complexity
ays-pro CWE-79
6.1
2023-06-21 CVE-2023-27414 Cross-site Scripting vulnerability in Ays-Pro Popup BOX
Unauth.
network
low complexity
ays-pro CWE-79
6.1
2023-06-12 CVE-2023-2568 Unspecified vulnerability in Ays-Pro Photo Gallery
The Photo Gallery by Ays WordPress plugin before 5.1.7 does not escape some parameters before outputting it back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
network
low complexity
ays-pro
6.1
2023-06-05 CVE-2023-2571 Unspecified vulnerability in Ays-Pro Quiz Maker
The Quiz Maker WordPress plugin before 6.4.2.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
network
low complexity
ays-pro
6.1
2023-06-05 CVE-2023-2572 Unspecified vulnerability in Ays-Pro Survey Maker
The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
network
low complexity
ays-pro
6.1
2023-01-20 CVE-2023-23490 SQL Injection vulnerability in Ays-Pro Survey Maker
The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the 'surveys_ids' parameter of its 'ays_surveys_export_json' action.
network
low complexity
ays-pro CWE-89
8.8
2023-01-03 CVE-2023-0038 Unspecified vulnerability in Ays-Pro Survey Maker
The "Survey Maker – Best WordPress Survey Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via survey answers in versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping.
network
low complexity
ays-pro
6.1
2022-05-30 CVE-2022-1456 Cross-site Scripting vulnerability in Ays-Pro Poll Maker
The Poll Maker WordPress plugin before 4.0.2 does not sanitise and escape some settings, which could allow high privilege users such as admin to perform Store Cross-Site Scripting attack even when unfiltered_html is disallowed
network
ays-pro CWE-79
3.5
2022-05-09 CVE-2022-1013 SQL Injection vulnerability in Ays-Pro Personal Dictionary
The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability.
network
low complexity
ays-pro CWE-89
7.5