plugin

Question Answer Vulnerabilities

7 known security issues reported for the Question Answer WordPress plugin. Most recent disclosed Jul 27, 2026.

2 high 2 medium

Running Question Answer on your site? Check whether your installed version is affected.

Scan your site free

PickPlugins Question Answer <= 1.2.73 - Unauthenticated SQL Injection via 'id' Parameter

high

The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.73. This is due to insufficient sanitization of user-supplied input via the 'id' GET parameter in the user profile template combined with the use of wp_unslash() which removes WordPress's magic quotes...

CVSS:
7.5
Affected:
up to 1.2.73
Fix:
No patched version reported
Disclosed:
Jul 27, 2026

CVE-2026-10207 on NVD →

Question Answer [question-answer] <= 1.2.70 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Question Answer allows Reflected XSS. This issue affects Question Answer: from n/a through 1.2.70.

Affected:
up to 1.2.70
Fix:
No patched version reported
Disclosed:
Apr 17, 2025

CVE-2025-32646 on NVD →

Question Answer [question-answer] <= 1.2.70 (unfixed)

unknown

[en] Deserialization of Untrusted Data vulnerability in PickPlugins Question Answer allows Object Injection. This issue affects Question Answer: from n/a through 1.2.70.

Affected:
up to 1.2.70
Fix:
No patched version reported
Disclosed:
Apr 17, 2025

CVE-2025-32647 on NVD →

Question Answer <= 1.2.70 - Authenticated (Subscriber+) PHP Object Injection

high

The Question Answer plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.70 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnera...

CVSS:
8.8
Affected:
up to 1.2.70
Fix:
No patched version reported
Disclosed:
Apr 14, 2025

CVE-2025-32647 on NVD →

Question Answer <= 1.2.70 - Reflected Cross-Site Scripting

medium

The Question Answer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2.70 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfull...

CVSS:
6.1
Affected:
up to 1.2.70
Fixed in:
1.2.71
Disclosed:
Apr 10, 2025

CVE-2025-32646 on NVD →

Question Answer <= 1.2.70 - Missing Authorization

medium

The Question Answer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.2.70. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.2.70
Fix:
No patched version reported
Disclosed:
Apr 1, 2025

CVE-2025-31810 on NVD →

Question Answer [question-answer] <= 1.2.70 (unfixed)

unknown

[en] Missing Authorization vulnerability in PickPlugins Question Answer allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Question Answer: from n/a through 1.2.70.

Affected:
up to 1.2.70
Fix:
No patched version reported
Disclosed:
Apr 1, 2025

CVE-2025-31810 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database