Survey Maker prior to 3.6.4 contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the website using the product with the administrative privilege.
References
| Link | Resource |
|---|---|
| https://jvn.jp/en/jp/JVN51098626/ | Third Party Advisory |
| https://wordpress.org/plugins/survey-maker/ | Product |
| https://jvn.jp/en/jp/JVN51098626/ | Third Party Advisory |
| https://wordpress.org/plugins/survey-maker/ | Product |
Configurations
History
10 Oct 2025, 17:18
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Ays-pro survey Maker
Ays-pro |
|
| References | () https://jvn.jp/en/jp/JVN51098626/ - Third Party Advisory | |
| References | () https://wordpress.org/plugins/survey-maker/ - Product | |
| CPE | cpe:2.3:a:ays-pro:survey_maker:*:*:*:*:*:wordpress:*:* |
Information
Published : 2024-04-03 08:15
Updated : 2025-10-10 17:18
NVD link : CVE-2023-34423
Mitre link : CVE-2023-34423
CVE.ORG link : CVE-2023-34423
JSON object : View
Products Affected
ays-pro
- survey_maker
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
