Input validation vulnerability in CM FAQ – Simplify support with an intuitive FAQ management tool 1.2.5

A popular plugin for managing frequently asked questions on WordPress websites, called CM FAQ, has a security issue that could put users at risk. This is because the plugin does not properly protect against a type of cyber attack called Reflected Cross-Site Scripting. This vulnerability exists in all versions of the plugin up to 1.2.5, which means that anyone using this plugin could be affected. Essentially, this means that hackers could inject harmful code into a website if they can convince a user to click on a link.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.