Back to search
CVE-2019-25297
Published: Jan 16, 2026
Modified: Jan 16, 2026
PUBLISHED
Description
Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site scripting (XSS) vulnerability via multiple parameters due to insufficient input validation and output escaping. An unauthenticated attacker can inject arbitrary script into content that executes when a victim views an affected page.
| Vendor | Product | Versions |
|---|---|---|
Assaf Parag | Poll, Survey & Quiz Maker Plugin by Opinion Stage | affected 0 - < 19.6.25 |
Weaknesses (CWE)
References
https://wpscan.com/vulnerability/4ed1edd6-3813-44a3-bee7-f07c1774b679/
third-party-advisory
patch
https://wordpress.org/plugins/social-polls-by-opinionstage/
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now