plugin

Ultimate Faqs Vulnerabilities

15 known security issues reported for the Ultimate Faqs WordPress plugin. Most recent disclosed Apr 8, 2026.

1 critical 6 medium

Running Ultimate Faqs on your site? Check whether your installed version is affected.

Scan your site free

Ultimate FAQ Accordion Plugin <= 2.4.7 - Authenticated (Author+) Stored Cross-Site Scripting via FAQ Content

medium

The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all versions up to, and including, 2.4.7. This is due to the plugin calling html_entity_decode() on post_content during rendering in the set_display_variables() function (View.FAQ.class.php, line 746), which...

CVSS:
6.4
Affected:
up to 2.4.7
Fixed in:
2.4.8
Disclosed:
Apr 8, 2026

CVE-2026-4336 on NVD →

Ultimate FAQ Accordion Plugin [ultimate-faqs] <= 2.4.3 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate FAQ ultimate-faqs allows Cross Site Request Forgery.This issue affects Ultimate FAQ: from n/a through <= 2.4.3.

Affected:
up to 2.4.3
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-67590 on NVD →

Ultimate FAQ <= 2.4.3 - Cross-Site Request Forgery

medium

The Ultimate FAQ Accordion Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can tric...

CVSS:
4.3
Affected:
up to 2.4.3
Fixed in:
2.4.4
Disclosed:
Nov 8, 2025

CVE-2025-67590 on NVD →

Ultimate FAQ Accordion Plugin [ultimate-faqs] < 2.1.2

unknown

[en] The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ and FAQ questions

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Jan 24, 2022

CVE-2021-24968 on NVD →

Ultimate FAQ <= 2.1.1 - Missing Authorization to Arbitrary FAQ Creation

medium

The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ and FAQ questions

CVSS:
5.7
Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Dec 27, 2021

CVE-2021-24968 on NVD →

Ultimate FAQ Accordion Plugin [ultimate-faqs] < 1.8.30

unknown

[en] The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.

Affected:
up to 1.8.30
Fixed in:
1.8.30
Disclosed:
Jan 16, 2020

CVE-2020-7107 on NVD →

Ultimate FAQ Accordion Plugin [ultimate-faqs] < 1.8.30

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found in WordPress Ultimate FAQ plugin (versions <= 1.8.29).

Affected:
up to 1.8.30
Fixed in:
1.8.30
Disclosed:
Jan 7, 2020

Ultimate FAQ <= 1.8.29 - Reflected Cross-Site Scripting

medium

The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.

CVSS:
6.1
Affected:
up to 1.8.29
Fixed in:
1.8.30
Disclosed:
Jan 6, 2020

CVE-2020-7107 on NVD →

Ultimate FAQ Accordion Plugin [ultimate-faqs] < 1.8.25

unknown

[en] Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.

Affected:
up to 1.8.25
Fixed in:
1.8.25
Disclosed:
Oct 7, 2019

CVE-2019-17233 on NVD →

Ultimate FAQ Accordion Plugin [ultimate-faqs] < 1.8.25

unknown

[en] Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.

Affected:
up to 1.8.25
Fixed in:
1.8.25
Disclosed:
Oct 7, 2019

CVE-2019-17232 on NVD →

Ultimate FAQ Accordion Plugin [ultimate-faqs] < 1.8.25

unknown

Unauthenticated Options Import/Export vulnerability found by Jerome Bruandet in WordPress Ultimate FAQ plugin (versions <= 1.8.24).

Affected:
up to 1.8.25
Fixed in:
1.8.25
Disclosed:
Sep 23, 2019

Ultimate FAQ <= 1.8.24 - Unauthenticated Options Import/Export

critical

Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.

CVSS:
9.1
Affected:
up to 1.8.25
Fixed in:
1.8.25
Disclosed:
Sep 20, 2019

CVE-2019-17232 on NVD →

Ultimate FAQ <= 1.8.24 - Cross-Site Scripting

medium

Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.

CVSS:
6.1
Affected:
up to 1.8.25
Fixed in:
1.8.25
Disclosed:
Sep 20, 2019

CVE-2019-17233 on NVD →

Ultimate FAQ Accordion Plugin [ultimate-faqs] < 1.8.22

unknown

[en] The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.

Affected:
up to 1.8.22
Fixed in:
1.8.22
Disclosed:
Aug 27, 2019

CVE-2019-15643 on NVD →

Ultimate Faqs <= 1.8.21 - Cross-Site Scripting

medium

The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.

CVSS:
6.1
Affected:
up to 1.8.22
Fixed in:
1.8.22
Disclosed:
May 8, 2019

CVE-2019-15643 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database