FS Product Inquiry <= 1.1.1 - Reflected XSS
Description
Reflected XSS in FS Product Inquiry plugin <=1.1.1 lets attackers inject arbitrary web scripts via unsanitized parameter, risking admin session theft.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Reflected XSS in FS Product Inquiry plugin <=1.1.1 lets attackers inject arbitrary web scripts via unsanitized parameter, risking admin session theft.
Vulnerability
The FS Product Inquiry WordPress plugin through version 1.1.1 fails to sanitize and escape a parameter before outputting it back in the page. This leads to a Reflected Cross-Site Scripting (XSS) vulnerability. The affected versions are all versions up to and including 1.1.1, as no fix has been released [1].
Exploitation
An attacker can craft a malicious URL that includes the unsanitized parameter, and then trick a user (including high-privilege users such as administrators, or unauthenticated users) into visiting that URL. The injected script executes in the context of the vulnerable WordPress site. No special authentication or network position is required beyond the ability to deliver the crafted link to the victim [1].
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser. This can lead to theft of session cookies, exfiltration of sensitive data, or actions performed on behalf of the victim, potentially resulting in full compromise of the affected WordPress site through an administrator account [1].
Mitigation
No official fix or patched version has been released by the plugin vendor as of the publication date (2024-06-04). The plugin is marked with no known fix [1]. Users should consider disabling or removing the plugin until a patched version is made available. No workarounds are documented in the available references.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- WordPress/FS Product Inquirydescription
- Range: <=1.1.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/6cf90a27-55e2-4b2c-9df1-5fa34c1bd9d1/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.