Junglewise Threat Intelligence

CVE-2026-57361: Ays Pro Survey Maker unauthenticated XSS

CVE-2026-57361 · Severity: high · CVSS 7.1 · Published 2026-07-02

Vendors: AYS Pro.

Executive brief

The Survey Maker plugin for WordPress, which is used to create and manage online surveys, contains a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could potentially hijack user sessions, redirect visitors to malicious websites, or deface the site. This vulnerability can be exploited by remote attackers without needing to log in to the site first.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Ays Pro Survey Maker plugin for WordPress (versions <= 5.2.2.5) due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject malicious JavaScript payloads that are executed in the context of a victim's browser. Exploitation requires a victim to perform a specific action, such as clicking a malicious link (User Interaction). Successful exploitation can lead to session hijacking, unauthorized actions on behalf of a privileged user, or information disclosure. The issue is resolved in version 5.2.2.6.

Affected products

  • Ays Pro Survey Maker <= 5.2.2.5

Timeline

  • 2026-04-29: disclosed: Reported by Nguyen Ba Khanh
  • 2026-07-01: advisory: Patchstack advisory published
  • 2026-07-02: patched: NVD publication and confirmation of patch in 5.2.2.6

References