CVE-2019-17233 is an HTML content injection vulnerability affecting the Functions/EWD_UFAQ_Import.php component of the ultimate-faqs plugin for WordPress, specifically versions up to 1.8.24. This medium-severity vulnerability (CVSS 6.1) can be exploited unauthenticated via a network attack requiring user interaction, potentially leading to limited impact on confidentiality and integrity. While not listed in CISA's KEV catalog, exploit intelligence indicates the existence of Nuclei templates for unauthenticated exploitation, and it has been referenced in media coverage regarding broader WordPress site compromises. Community discussion and media coverage suggest moderate attention to this flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.8.24CPE matchmatch criteria | cpe:2.3:a:etoilewebdesign:ultimate_faq:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.