Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
Survey Maker
Ays Pro
Developer
5.1.9.5
Latest version
6,000
Installations
6 days ago
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Vulnerability history
0 present
19 fixed
5 Mitigation rules
Broken Access Control vulnerability
<= 5.1.9.4
4 days ago
Missing Authorization to Unauthenticated Information Exposure vulnerability
<= 5.1.9.4
6 days ago
Cross Site Scripting (XSS) vulnerability
<= 5.1.8.8
Oct 9, 2025
Cross Site Scripting (XSS) vulnerability
<= 5.1.8.8
Oct 9, 2025
Bypass vulnerability
<= 5.1.6.3
Apr 7, 2025
Cross Site Scripting (XSS) vulnerability
<= 5.1.3.5
Feb 3, 2025
Authenticated (Admin+) Stored Cross-Site Scripting via Survey Question vulnerability
<= 5.1.3.3
Jan 30, 2025
Cross Site Scripting (XSS) vulnerability
<= 5.0.2
Oct 24, 2024
Authenticated (Admin+) Stored Cross-Site Scripting vulnerability
<= 4.9.5
Oct 8, 2024
Admin+ Stored XSS via Plugin Settings vulnerability
< 4.2.9
May 21, 2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 4.0.6
Mar 25, 2024
Cross Site Scripting (XSS) vulnerability
<= 4.0.5
Mar 15, 2024
Reflected XSS vulnerability
< 3.4.7
Jun 22, 2023
Broken Access Control vulnerability
<= 3.2.0
Jan 27, 2023
Authenticated SQL Injection Vulnerability
<= 3.1.1
Jan 14, 2023
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 3.1.3
Jan 3, 2023
Authenticated (Admin+) Stored Cross-Site Scripting vulnerability
<= 3.1.1
Dec 23, 2022
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 2.0.6
Dec 3, 2021
Authenticated Blind SQL Injection (SQLi) vulnerability
<= 1.5.5
Jun 29, 2021