CVE-2026-26370 MEDIUM

CVE-2026-26370

Vendor Ays Pro
Product Survey Maker
Weakness CWE-79 · XSS
Published February 20, 2026
Last update February 20, 2026

CVSS base score

6.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

WordPress Plugin "Survey Maker" versions 5.1.7.7 and prior contain a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.

Explanation of Vulnerability in Simple Terms

02Summary

Survey Maker versions 5.1.7.7 and prior contain a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into survey pages. An attacker can craft a malicious link or embed code that executes in a victim's browser when they view the affected survey. The vulnerability affects the site's integrity and can compromise user data or session tokens.

What an attacker can do

03Attacker Capabilities

Inject malicious JavaScript that runs in visitors' browsers when they view a survey.

Potential impact on your site

04Site Impact

Attackers can steal visitor session tokens, redirect users, or deface survey content without needing site admin access.

Conditions required to exploit

05Prerequisites

Victim must click a malicious link or visit a page containing the attacker's payload.

Key dates

06Disclosure timeline

February 20, 2026 CVE published
February 20, 2026 Record updated

Related vulnerabilities

08Related CVE