CVE Database
/

CVE-2019-25297

Back to search

CVE-2019-25297

Published: Jan 16, 2026

Modified: Jan 16, 2026

PUBLISHED

Description

Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site scripting (XSS) vulnerability via multiple parameters due to insufficient input validation and output escaping. An unauthenticated attacker can inject arbitrary script into content that executes when a victim views an affected page.

VendorProductVersions

Assaf Parag

Poll, Survey & Quiz Maker Plugin by Opinion Stage

affected
0 - < 19.6.25

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now