N/A
2026-04-09< 2.4.8
WordPress Ultimate FAQ Plugin <= 2.4.7 is vulnerable to Cross Site Scripting (XSS)
Minimum safe version
2.4.8
Update to 2.4.8 or later to address 9 fixable vulnerabilities
WordPress Ultimate FAQ Plugin <= 2.4.7 is vulnerable to Cross Site Scripting (XSS)
CVE-2025-67590
WordPress Ultimate FAQ plugin <= 1.8.24 - Unauthenticated Options Import/Export vulnerability
WordPress Ultimate FAQ plugin <= 1.8.29 - Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability
CVE-2019-15643
CVE-2019-17232
CVE-2019-17233
CVE-2020-7107
CVE-2021-24968