Medium severity6.1NVD Advisory· Published Jan 16, 2020· Updated Jun 17, 2026
CVE-2020-7107
CVE-2020-7107
Description
The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:etoilewebdesign:ultimate_faq:*:*:*:*:*:wordpress:*:*Range: <1.8.30
Patches
Vulnerability mechanics
References
3- plugins.trac.wordpress.org/changeset/2222959/ultimate-faqs/tags/1.8.30/Shortcodes/DisplayFAQs.phpnvdPatchThird Party Advisory
- wordpress.org/plugins/ultimate-faqs/nvdThird Party Advisory
- wpvulndb.com/vulnerabilities/10006nvdThird Party Advisory
News mentions
0No linked articles in our index yet.