Description
Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the Questions field in an "Add New FAQ" action.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Code Highlight.js Cross-Site Scripting (0.6.3)
WordPress Plugin Quiz and Survey Master (QSM)-Easy Quiz and Survey Maker SQL Injection (7.1.13)
WordPress Plugin CigiCigi Post Guest Cross-Site Scripting (1.0.5)
WordPress Plugin WPS Cleaner Multiple Cross-Site Request Forgery Vulnerabilities (1.4.4)