CVE-2026-81737

8.8

AYS Pro · FAQ Builder AYS

A stored cross-site scripting (XSS) vulnerability in the FAQ Builder AYS WordPress plugin allows unauthenticated attackers to execute malicious scripts in the context of an administrator.

Executive summary

A high-severity stored cross-site scripting vulnerability in the FAQ Builder AYS WordPress plugin enables unauthenticated attackers to execute arbitrary code within an administrator's browser session.

Vulnerability

The plugin fails to properly sanitize or escape input submitted by unauthenticated visitors, and a flawed decoding process undermines existing security controls, resulting in stored cross-site scripting (XSS) that triggers when an administrator views the affected content.

Business impact

This vulnerability carries a CVSS score of 8.8, reflecting its potential for severe impact on organizational integrity. Successful exploitation allows an attacker to perform unauthorized actions on behalf of a site administrator, potentially leading to full site compromise, the theft of sensitive administrative sessions, or the redirection of site traffic to malicious domains.

Remediation

Immediate Action: Update the FAQ Builder AYS plugin to version 1.8.5 or later immediately to resolve the identified sanitation flaws.

Proactive Monitoring: Audit administrative logs for unusual activity or unauthorized configuration changes that may indicate a successful XSS-based account takeover.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common cross-site scripting payloads directed at WordPress endpoints.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit available in the provided data.

Analyst recommendation

Given the High severity of this vulnerability, administrators should prioritize the application of the vendor-provided patch. Failure to update the plugin leaves the administrative interface exposed to unauthorized script execution, which could result in a complete loss of site control.

More AYS Pro CVEs

Sources

Originally found and disclosed by Pablo González Pérez, Francisco José Ramírez Vicente and Iñigo Sánchez Enciso, with WPScan (coordinator), per the CVE Program record.