WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Happy FAQs – WordPress FAQ and Product FAQ

WordPress FAQ and WooCommerce product FAQ plugin with accordion layouts, Google FAQ schema, AI generator, Gutenberg, Elementor, Divi, and shortcodes.

3Reported vulnerabilities
6.4Highest CVSS score
2.0.1Latest version
1,000+Active installs

What to do now

Update Happy FAQs – WordPress FAQ and Product FAQ to 1.7.1 or later. 3 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 17, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2024-5669 Medium 6.4 0.4% 0 to 1.7.0 (inclusive) 1.7.1 July 9, 2024
CVE-2024-37515 Medium 6.1 0.2% 1.6.3 and earlier 1.6.4 July 5, 2024
CVE-2024-5704 Medium 4.3 0.4% 0 to 1.7.0 (inclusive) 1.7.1 July 9, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.