Description inc/PMF/Faq.php in phpMyFAQ before 2.9.7 has XSS in the question field. Remediation References CVE-2017-7579 Related Vulnerabilities WordPress Plugin Management App for WooCommerce-Order notifications, Order management, Lead management, Uptime Monitoring Unspecified Vulnerability (1.2.3) Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2018-6376) Moodle Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2016-9186) WordPress Plugin User Meta Manager Multiple Vulnerabilities (3.4.6) WordPress Plugin Share Woocommerce to Email Cross-Site Scripting (1.0.1) Severity Medium Classification CVE-2017-7579 CWE-707 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities