Cross‑Site Scripting in WordPress Survey Maker Plugin
Survey Maker by AYS
Minimum safe version
5.1.9.5
Update to 5.1.9.5 or later to address 25 fixable vulnerabilities
CVE-2025-12891
CVE-2025-12892
Survey Maker <= 5.1.9.4 - Missing Authorization
CVE-2025-48095
CVE-2025-48098
CVE-2025-32275
CVE-2025-22664
WordPress Survey Maker Plugin <= 5.1.3.3 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-50426
CVE-2024-8488
CVE-2024-4061
CVE-2023-35764
Survey Maker – Best WordPress Survey Plugin <= 3.6.6 - Unauthenticated Stored Cross-Site Scripting
CVE-2024-29918
CVE-2024-27996
WordPress Survey Maker Plugin < 3.4.7 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-22697
CVE-2023-23490
CVE-2023-0038
Survey Maker – Best WordPress Survey Plugin <= 3.1.1 - Authenticated (Admin+) Stored Cross-Site Scripting
WordPress Survey Maker Plugin <= 3.1.1 is vulnerable to Cross Site Scripting (XSS)
Survey Maker – Best WordPress Survey Plugin <= 1.5.5 - Reflected Cross-Site Scripting
Multiple Plugins from AYS Pro - Reflected Cross-Site Scripting (XSS)
CVE-2021-24459
CVE-2021-26256