Ays Pro develops a focused suite of web-based interactive content tools including poll makers, quiz makers, survey platforms, popup boxes, and photo galleries that are widely embedded across websites for user engagement and data collection. The vendor's modest CVE footprint, concentrated across this narrow product line, reflects the relatively constrained attack surface of client-side content-generation and display components. Recurring weakness classes have not emerged as a defining pattern across the disclosed vulnerabilities. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ays Pro over time
Signals from CVEs in this vendor scope (110 CVEs).
110 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24931CRITICAL The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (availabl | Dec 6, 2021 | 9.8 | 91 | NO | YES |
CVE-2024-6028CRITICAL The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient es | Jun 25, 2024 | 9.8 | 46 | NO | YES |
CVE-2022-1013CRITICAL The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, lead | May 9, 2022 | 9.8 | 45 | NO | YES |
CVE-2024-10571CRITICAL The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the 'source' parameter. This makes | Nov 14, 2024 | 9.8 | 43 | NO | YES |
CVE-2025-10042HIGH The Quiz Maker plugin for WordPress is vulnerable to SQL Injection via spoofed IP headers in all versions up to, and including, 6.7.0.56 due to insufficient escaping on the user su | Sep 17, 2025 | 7.5 | 37 | NO | YES |
CVE-2026-57631HIGH Administrator SQL Injection in Popup box <= 6.0.1 versions. | Jun 26, 2026 | 7.6 | 32 | NO | NO |
CVE-2024-7714HIGH The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBo | Sep 27, 2024 | 7.5 | 32 | NO | YES |
CVE-2025-30774CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker quiz-maker allows SQL Injection.This issue affects Quiz Mak | Apr 1, 2025 | 9.8 | 30 | NO | NO |
CVE-2026-57361HIGH Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.2.5 versions. | Jul 2, 2026 | 7.1 | 29 | NO | NO |
CVE-2023-23490HIGH The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the 'surveys_ids' parameter of its 'ays_surveys_export_json' acti | Jan 20, 2023 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (110 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ays Pro.
Media articles that mention a CVE ID that affects a product developed by Ays Pro — matched by CVE ID, not by vendor name.