CVE-2026-26370: Ays Pro Survey Maker

Medium severity, CVSS 5.1. EPSS: 0.3% chance of exploitation in the next 30 days.

WordPress Plugin "Survey Maker" versions 5.1.7.7 and prior contain a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.

Affected products

  • Ays Pro Survey Maker: up to and including 5.1.7.7

Published 2026-02-20. Last modified 2026-06-17.