DS FAQ Plus
DS FAQ Plus has one disclosed vulnerability in the WordSec catalog, all reported in 2020; it is fixed as of September 2026. Their average CVSS score is 7.1, and the most serious one scores 7.1 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for DS FAQ Plus has a vendor fix available, so running the current release closes it.
All of these findings were reported by Wilco de Jongh. DS FAQ Plus is installed on roughly 30 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
WP DS FAQ Plus < 1.4.2 - Cross-Site Scripting
Read the full analysisVulnerability Records
DS FAQ Plus
Author
kimipooh
WP DS FAQ Plus is the plugin which was improved based on WP DS FAQ 1.3.3. This plugin includes the fixed some issues (Quotation and Security, such as SQL Injection and CSRF. ) , Japanese translation, improvement of interface, and SSL Admin setting. 2.0.0 Major refactoring and modernization of the plugin. Security Improvements * SQL queries rewritten using $wpdb->prepare(), $wpdb->insert(), $wpdb->update() * Nonce verification added for admin and AJAX actions * Sanitization added for user input WordPress Compatibility * Replaced deprecated date() usage with wp_date() * Implemented WordPress timezone handling Database Handling * Introduced dbDelta() for automatic table creation and schema updates Architecture Improvements * ajax.php removed * Bootstrap loader separated from main implementation Plugin Check * Plugin Check validation completed * All errors resolved except “trademarked_term” Note on Plugin Name WP DS FAQ Plus is an independent plugin for WordPress and is not affiliated with or endorsed by the WordPress project.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C