WordPress security by component
Spiritual Gifts Survey (and optional S.H.A.P.E survey)
Plugin description
Spiritual Gifts Survey (and optional S.H.A.P.E survey) is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published May 15, 2025; the highest CVE/CNA score is 6.1.
Plugin slug:
spiritual-gifts-survey-and-optional-s-h-a-p-e-surveyLatest vulnerability
CVE-2025-0688: Spiritual Gifts Survey (and optional S.H.A.P.E survey): Cross-site scripting
Spiritual Gifts Survey (and optional S.H.A.P.E survey) is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
| Safe version |
|
||
|---|---|---|---|
| May 15, 2025 |
CVE-2025-0688
Spiritual Gifts Survey (and optional S.H.A.P.E survey): Cross-site scripting
Spiritual Gifts Survey (and optional S.H.A.P.E survey) is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| May 15, 2025 |
CVE-2025-0687
Spiritual Gifts Survey (and optional S.H.A.P.E survey): Cross-site scripting
Spiritual Gifts Survey (and optional S.H.A.P.E survey) is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|