HomeWordPress vulnerabilitiesUltimate FAQ Accordion Plugin
Ultimate FAQ Accordion Plugin vulnerabilities
Ultimate FAQ Accordion Plugin has 5 known vulnerabilities in this database. The most recent published record is dated 9 Apr 2026.
- Known vulnerabilities
- 5
- Active installs
- 30,000+
- Latest version
- 2.5.0
- Last updated
- 21 Sep 2026
- Most recent
- 9 Apr 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Cross-site scripting (XSS) CVE-2026-4336 | Medium 6.4 | Up to 2.4.7 | Fixed in a later version (latest 2.5.0) | 9 Apr 2026 |
| Cross-site scripting (XSS) CVE-2020-7107 | Medium 6.1 | Before 1.8.30 | Fixed in 1.8.30 | 16 Jan 2020 |
| Authentication bypass CVE-2019-17232 | High 7.5 | Up to 1.8.24 | Fixed in a later version (latest 2.5.0) | 7 Oct 2019 |
| Content injection CVE-2019-17233 | Medium 6.1 | Up to 1.8.24 | Fixed in a later version (latest 2.5.0) | 7 Oct 2019 |
| Cross-site scripting (XSS) CVE-2019-15643 | Medium 6.1 | Before 1.8.22 | Fixed in 1.8.22 | 27 Aug 2019 |
Read the published descriptions
- CVE-2026-4336, 9 Apr 2026
- The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all versions up to, and including, 2.4.7. This is due to the plugin calling html_entity_decode() on post_content during rendering in the set_display_variables() function (View.FAQ.class.php, line 746), which converts HTML entity-encoded payloads back into executable HTML, combined with insufficient output escaping in the faq-answer.php template where the decoded content is echoed without wp_kses_post() or any other sanitization. The ufaq custom post type is registered with 'show_in_rest' => true and defaults to 'post' capability_type, allowing Author-level users to create and publish FAQs via the REST API. An Author can submit entity-encoded malicious HTML (e.g., <img src=x onerror=alert()>) which bypasses WordPress's kses sanitization at save time (since kses sees entities as plain text, not tags), but is then decoded back into executable HTML by html_entity_decode() at render time. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in FAQ pages that will execute whenever a user accesses an injected FAQ, either directly or via the [ultimate-faqs] shortcode. CVE record
- CVE-2020-7107, 16 Jan 2020
- The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php. CVE record
- CVE-2019-17232, 7 Oct 2019
- Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import. CVE record
- CVE-2019-17233, 7 Oct 2019
- Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection. CVE record
- CVE-2019-15643, 27 Aug 2019
- The ultimate-faqs plugin before 1.8.22 for WordPress has XSS. CVE record
What to do if you run Ultimate FAQ Accordion Plugin
If you run Ultimate FAQ Accordion Plugin, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Ultimate FAQ Accordion Plugin vulnerabilities
Free. We email you when a new vulnerability is published for Ultimate FAQ Accordion Plugin, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.