PickPlugins Question Answer <= 1.2.73 - Unauthenticated SQL Injection via 'id' Parameter
high
The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.73. This is due to insufficient sanitization of user-supplied input via the 'id' GET parameter in the user profile template combined with the use of wp_unslash() which removes WordPress's magic quotes...
- CVSS:
- 7.5
- Affected:
- up to 1.2.73
- Fix:
- No patched version reported
- Disclosed:
- Jul 27, 2026
CVE-2026-10207 on NVD →
Question Answer [question-answer] <= 1.2.70 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Question Answer allows Reflected XSS. This issue affects Question Answer: from n/a through 1.2.70.
- Affected:
- up to 1.2.70
- Fix:
- No patched version reported
- Disclosed:
- Apr 17, 2025
CVE-2025-32646 on NVD →
Question Answer [question-answer] <= 1.2.70 (unfixed)
unknown
[en] Deserialization of Untrusted Data vulnerability in PickPlugins Question Answer allows Object Injection. This issue affects Question Answer: from n/a through 1.2.70.
- Affected:
- up to 1.2.70
- Fix:
- No patched version reported
- Disclosed:
- Apr 17, 2025
CVE-2025-32647 on NVD →
Question Answer <= 1.2.70 - Authenticated (Subscriber+) PHP Object Injection
high
The Question Answer plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.70 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnera...
- CVSS:
- 8.8
- Affected:
- up to 1.2.70
- Fix:
- No patched version reported
- Disclosed:
- Apr 14, 2025
CVE-2025-32647 on NVD →
Question Answer <= 1.2.70 - Reflected Cross-Site Scripting
medium
The Question Answer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2.70 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfull...
- CVSS:
- 6.1
- Affected:
- up to 1.2.70
- Fixed in:
- 1.2.71
- Disclosed:
- Apr 10, 2025
CVE-2025-32646 on NVD →
Question Answer <= 1.2.70 - Missing Authorization
medium
The Question Answer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.2.70. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.2.70
- Fix:
- No patched version reported
- Disclosed:
- Apr 1, 2025
CVE-2025-31810 on NVD →
Question Answer [question-answer] <= 1.2.70 (unfixed)
unknown
[en] Missing Authorization vulnerability in PickPlugins Question Answer allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Question Answer: from n/a through 1.2.70.
- Affected:
- up to 1.2.70
- Fix:
- No patched version reported
- Disclosed:
- Apr 1, 2025
CVE-2025-31810 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database