Vulnerability Description
Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site scripting (XSS) vulnerability via multiple parameters due to insufficient input validation and output escaping. An unauthenticated attacker can inject arbitrary script into content that executes when a victim views an affected page.
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/changeset/2158590/social-polls-by-opinionstag
- https://web.archive.org/web/20191020011448/https://www.pluginvulnerabilities.com
- https://wordpress.org/plugins/social-polls-by-opinionstage/
- https://wpscan.com/vulnerability/4ed1edd6-3813-44a3-bee7-f07c1774b679/
- https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-poll-survey-form-q
- https://www.vulncheck.com/advisories/poll-survey-and-quiz-maker-plugin-by-opinio
- https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/social-
- https://web.archive.org/web/20191020011448/https://www.pluginvulnerabilities.com
- https://wpscan.com/vulnerability/4ed1edd6-3813-44a3-bee7-f07c1774b679/
FAQ
What is CVE-2019-25297?
CVE-2019-25297 is a documented vulnerability. Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site scripting (XSS) vulnerability via multiple parameters due to insufficient input...
How severe is CVE-2019-25297?
CVSS scoring is not yet available for CVE-2019-25297. Check NVD for updates.
Is there a patch for CVE-2019-25297?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.