Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesUltimate FAQ Accordion Plugin

Ultimate FAQ Accordion Plugin vulnerabilities

Ultimate FAQ Accordion Plugin has 5 known vulnerabilities in this database. The most recent published record is dated 9 Apr 2026.

Known vulnerabilities
5
Active installs
30,000+
Latest version
2.5.0
Last updated
21 Sep 2026
Most recent
9 Apr 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Cross-site scripting (XSS)
CVE-2026-4336
Medium 6.4Up to 2.4.7Fixed in a later version (latest 2.5.0)9 Apr 2026
Cross-site scripting (XSS)
CVE-2020-7107
Medium 6.1Before 1.8.30Fixed in 1.8.3016 Jan 2020
Authentication bypass
CVE-2019-17232
High 7.5Up to 1.8.24Fixed in a later version (latest 2.5.0)7 Oct 2019
Content injection
CVE-2019-17233
Medium 6.1Up to 1.8.24Fixed in a later version (latest 2.5.0)7 Oct 2019
Cross-site scripting (XSS)
CVE-2019-15643
Medium 6.1Before 1.8.22Fixed in 1.8.2227 Aug 2019
Read the published descriptions
CVE-2026-4336, 9 Apr 2026
The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all versions up to, and including, 2.4.7. This is due to the plugin calling html_entity_decode() on post_content during rendering in the set_display_variables() function (View.FAQ.class.php, line 746), which converts HTML entity-encoded payloads back into executable HTML, combined with insufficient output escaping in the faq-answer.php template where the decoded content is echoed without wp_kses_post() or any other sanitization. The ufaq custom post type is registered with 'show_in_rest' => true and defaults to 'post' capability_type, allowing Author-level users to create and publish FAQs via the REST API. An Author can submit entity-encoded malicious HTML (e.g., <img src=x onerror=alert()>) which bypasses WordPress's kses sanitization at save time (since kses sees entities as plain text, not tags), but is then decoded back into executable HTML by html_entity_decode() at render time. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in FAQ pages that will execute whenever a user accesses an injected FAQ, either directly or via the [ultimate-faqs] shortcode. CVE record
CVE-2020-7107, 16 Jan 2020
The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php. CVE record
CVE-2019-17232, 7 Oct 2019
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import. CVE record
CVE-2019-17233, 7 Oct 2019
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection. CVE record
CVE-2019-15643, 27 Aug 2019
The ultimate-faqs plugin before 1.8.22 for WordPress has XSS. CVE record

What to do if you run Ultimate FAQ Accordion Plugin

If you run Ultimate FAQ Accordion Plugin, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Ultimate FAQ Accordion Plugin vulnerabilities

Free. We email you when a new vulnerability is published for Ultimate FAQ Accordion Plugin, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support