Ultimate FAQ Accordion Plugin <= 2.4.7 - Authenticated (Author+) Stored Cross-Site Scripting via FAQ Content
medium
The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all versions up to, and including, 2.4.7. This is due to the plugin calling html_entity_decode() on post_content during rendering in the set_display_variables() function (View.FAQ.class.php, line 746), which...
- CVSS:
- 6.4
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.8
- Disclosed:
- Apr 8, 2026
CVE-2026-4336 on NVD →
Ultimate FAQ Accordion Plugin [ultimate-faqs] <= 2.4.3 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate FAQ ultimate-faqs allows Cross Site Request Forgery.This issue affects Ultimate FAQ: from n/a through <= 2.4.3.
- Affected:
- up to 2.4.3
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-67590 on NVD →
Ultimate FAQ <= 2.4.3 - Cross-Site Request Forgery
medium
The Ultimate FAQ Accordion Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can tric...
- CVSS:
- 4.3
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.4
- Disclosed:
- Nov 8, 2025
CVE-2025-67590 on NVD →
Ultimate FAQ Accordion Plugin [ultimate-faqs] < 2.1.2
unknown
[en] The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ and FAQ questions
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Jan 24, 2022
CVE-2021-24968 on NVD →
Ultimate FAQ <= 2.1.1 - Missing Authorization to Arbitrary FAQ Creation
medium
The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ and FAQ questions
- CVSS:
- 5.7
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Dec 27, 2021
CVE-2021-24968 on NVD →
Ultimate FAQ Accordion Plugin [ultimate-faqs] < 1.8.30
unknown
[en] The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.
- Affected:
- up to 1.8.30
- Fixed in:
- 1.8.30
- Disclosed:
- Jan 16, 2020
CVE-2020-7107 on NVD →
Ultimate FAQ Accordion Plugin [ultimate-faqs] < 1.8.30
unknown
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found in WordPress Ultimate FAQ plugin (versions <= 1.8.29).
- Affected:
- up to 1.8.30
- Fixed in:
- 1.8.30
- Disclosed:
- Jan 7, 2020
Ultimate FAQ <= 1.8.29 - Reflected Cross-Site Scripting
medium
The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.
- CVSS:
- 6.1
- Affected:
- up to 1.8.29
- Fixed in:
- 1.8.30
- Disclosed:
- Jan 6, 2020
CVE-2020-7107 on NVD →
Ultimate FAQ Accordion Plugin [ultimate-faqs] < 1.8.25
unknown
[en] Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.
- Affected:
- up to 1.8.25
- Fixed in:
- 1.8.25
- Disclosed:
- Oct 7, 2019
CVE-2019-17233 on NVD →
Ultimate FAQ Accordion Plugin [ultimate-faqs] < 1.8.25
unknown
[en] Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.
- Affected:
- up to 1.8.25
- Fixed in:
- 1.8.25
- Disclosed:
- Oct 7, 2019
CVE-2019-17232 on NVD →
Ultimate FAQ Accordion Plugin [ultimate-faqs] < 1.8.25
unknown
Unauthenticated Options Import/Export vulnerability found by Jerome Bruandet in WordPress Ultimate FAQ plugin (versions <= 1.8.24).
- Affected:
- up to 1.8.25
- Fixed in:
- 1.8.25
- Disclosed:
- Sep 23, 2019
Ultimate FAQ <= 1.8.24 - Unauthenticated Options Import/Export
critical
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.
- CVSS:
- 9.1
- Affected:
- up to 1.8.25
- Fixed in:
- 1.8.25
- Disclosed:
- Sep 20, 2019
CVE-2019-17232 on NVD →
Ultimate FAQ <= 1.8.24 - Cross-Site Scripting
medium
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.
- CVSS:
- 6.1
- Affected:
- up to 1.8.25
- Fixed in:
- 1.8.25
- Disclosed:
- Sep 20, 2019
CVE-2019-17233 on NVD →
Ultimate FAQ Accordion Plugin [ultimate-faqs] < 1.8.22
unknown
[en] The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.
- Affected:
- up to 1.8.22
- Fixed in:
- 1.8.22
- Disclosed:
- Aug 27, 2019
CVE-2019-15643 on NVD →
Ultimate Faqs <= 1.8.21 - Cross-Site Scripting
medium
The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.
- CVSS:
- 6.1
- Affected:
- up to 1.8.22
- Fixed in:
- 1.8.22
- Disclosed:
- May 8, 2019
CVE-2019-15643 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database