DS FAQ Plus

DS FAQ Plus has one disclosed vulnerability in the WordSec catalog, all reported in 2020; it is fixed as of September 2026. Their average CVSS score is 7.1, and the most serious one scores 7.1 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for DS FAQ Plus has a vendor fix available, so running the current release closes it.

All of these findings were reported by Wilco de Jongh. DS FAQ Plus is installed on roughly 30 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSHigh
7.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all DS FAQ Plus vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.1

WP DS FAQ Plus < 1.4.2 - Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Plugin Profile
Latestv2.1.0

DS FAQ Plus

kimipooh

Author

kimipooh

5.0(1)
100/100
Last Updated
2026-05-17 (4mo ago)
Active Installs
30+
Downloads
17,315
Requires WP
6.0+
Requires PHP
8.0+
Tested up to
WP 7.0.4
Created
2012-07-09 (14y ago)

WP DS FAQ Plus is the plugin which was improved based on WP DS FAQ 1.3.3. This plugin includes the fixed some issues (Quotation and Security, such as SQL Injection and CSRF. ) , Japanese translation, improvement of interface, and SSL Admin setting. 2.0.0 Major refactoring and modernization of the plugin. Security Improvements * SQL queries rewritten using $wpdb->prepare(), $wpdb->insert(), $wpdb->update() * Nonce verification added for admin and AJAX actions * Sanitization added for user input WordPress Compatibility * Replaced deprecated date() usage with wp_date() * Implemented WordPress timezone handling Database Handling * Introduced dbDelta() for automatic table creation and schema updates Architecture Improvements * ajax.php removed * Bootstrap loader separated from main implementation Plugin Check * Plugin Check validation completed * All errors resolved except “trademarked_term” Note on Plugin Name WP DS FAQ Plus is an independent plugin for WordPress and is not affiliated with or endorsed by the WordPress project.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C