What this page helps you verify fast
This hub clusters every indexed record for Ultimate FAQ Accordion Plugin so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
Review known vulnerability records for the WordPress plugin Ultimate FAQ Accordion Plugin (`ultimate-faqs`), including severity, CVE references, affected versions, and patch status.
Recent tracked CVEs on this page include CVE-2026-4336, CVE-2025-67590 and CVE-2021-24968, so operators can jump from disclosure to patch validation without scanning the full feed first.
This hub clusters every indexed record for Ultimate FAQ Accordion Plugin so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
These recent records surface the CVE strings, patch cues, and direct report links most operators need first.
The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all versions up to, and including, 2.4.7. This is due to the plugin calling ht...
The Ultimate FAQ Accordion Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.3. This is due to missing or incorrect nonce vali...
The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authe...
Sorted by latest disclosure date so newly published issues surface first.
The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all versions up to, and including, 2.4.7. This is due to the plugin calling html_entity_decode() on post_content during rendering in the set_display_variables() functio...
The Ultimate FAQ Accordion Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an u...
The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ...
The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.
The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.