
CM FAQ – Simplify support with an intuitive FAQ management tool Security & Risk Analysis
wordpress.org/plugins/cm-faqCreate and manage a user-friendly FAQ section on your site with this FAQ plugin. Answer common questions and improve user experience.
Is CM FAQ – Simplify support with an intuitive FAQ management tool Safe to Use in 2026?
Generally Safe
Score 99/100CM FAQ – Simplify support with an intuitive FAQ management tool has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "cm-faq" plugin version 1.3.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices in its handling of SQL queries, with all queries utilizing prepared statements, and it includes a decent number of nonce checks and capability checks. However, several concerns detract from its overall security. The presence of three AJAX handlers without authentication checks presents a significant attack surface, potentially allowing unauthorized users to trigger functionalities. The taint analysis also revealed one flow with an unsanitized path, which, while not classified as critical or high severity in this specific analysis, could indicate potential for vulnerabilities if not properly handled in context.
The vulnerability history shows a single medium-severity CVE related to Cross-Site Scripting (XSS), which was last disclosed in March 2025. While this vulnerability is currently patched, the pattern suggests that XSS remains a potential concern for this plugin. The static analysis also indicates a concerningly low rate of proper output escaping (49%), which directly correlates with XSS vulnerabilities, as it means a substantial portion of user-generated or dynamic content might be rendered without adequate sanitization, leaving the application vulnerable to malicious script injection.
In conclusion, while the plugin has some strong security fundamentals like prepared SQL statements, the unprotected AJAX endpoints, the identified unsanitized path flow, and the high proportion of improperly escaped output create notable risks. The past XSS vulnerability further underscores the need for vigilance in output sanitization. Users should be aware of these potential weaknesses and ensure the plugin is kept up-to-date.
Key Concerns
- AJAX handlers without auth checks
- Low output escaping percentage
- Taint flow with unsanitized path
- Medium severity CVE history
CM FAQ – Simplify support with an intuitive FAQ management tool Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
CM FAQ – Simplify support with an intuitive FAQ management tool <= 1.2.5 - Reflected Cross-Site Scripting
CM FAQ – Simplify support with an intuitive FAQ management tool Release Timeline
CM FAQ – Simplify support with an intuitive FAQ management tool Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
CM FAQ – Simplify support with an intuitive FAQ management tool Attack Surface
AJAX Handlers 5
Shortcodes 5
WordPress Hooks 51
Maintenance & Trust
CM FAQ – Simplify support with an intuitive FAQ management tool Maintenance & Trust
Maintenance Signals
Community Trust
CM FAQ – Simplify support with an intuitive FAQ management tool Alternatives
Squelch Tabs and Accordions Shortcodes
squelch-tabs-and-accordions-shortcodes
Shortcodes for creating accordions, horizontal accordions and tabs.
Display FAQ – Responsive Accordion and Product FAQ For WooCommerce
wp-display-faq
Create and display responsive Accordions, FAQs in a webpage. Also create Product FAQ for WooCommerce and display them in a single product page.
Advanced Accordion Gutenberg Block – Create Beautiful FAQs, Content Accordions & Interactive Tabs
advanced-accordion-block
Create stunning FAQ & accordion blocks. SEO-optimized, fully accessible, zero performance impact. No coding needed.
Iks Menu – WordPress Category Accordion Menu & FAQs
iks-menu
Super customizable WordPress plugin for displaying custom menus, taxonomy/category terms and FAQs as accordion menu (with images support).
Quick and Easy FAQs
quick-and-easy-faqs
Truly a quick and easy way to add FAQs to your site.
CM FAQ – Simplify support with an intuitive FAQ management tool Developer Profile
19 plugins · 22K total installs
How We Detect CM FAQ – Simplify support with an intuitive FAQ management tool
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cm-faq/assets/backend/css/backend.css/wp-content/plugins/cm-faq/assets/backend/js/backend.js/wp-content/plugins/cm-faq/assets/frontend/css/frontend.css/wp-content/plugins/cm-faq/assets/frontend/js/frontend.js/wp-content/plugins/cm-faq/assets/backend/js/backend.js/wp-content/plugins/cm-faq/assets/frontend/js/frontend.jscm-faq/assets/backend/css/backend.css?ver=cm-faq/assets/backend/js/backend.js?ver=cm-faq/assets/frontend/css/frontend.css?ver=cm-faq/assets/frontend/js/frontend.js?ver=HTML / DOM Fingerprints
cmfaq-question-wrappercmfaq-title-wrappercmfaq-question-titlecmfaq-answer-wrappercmfaq-toggle-iconcmfaq-question-listcmfaq-category-listcmfaq-faq-search+6 more<!-- Main FAQ category --><!-- Voting --><!-- Chat GPT --><!-- FAQ Tags -->+3 moredata-cmfaq-iddata-cmfaq-categorydata-cmfaq-search-urldata-cmfaq-voting-urlCMFAQFrontend/wp-json/cmfaq/v1/vote[cm_faq]