CVE detail
CVE-2019-25297 — CVE-2019-25297
Published 2026-01-16 · Modified 2026-06-17 · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0046
EPSS probability
exploitation probability, 30d
38.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site scripting (XSS) vulnerability via multiple parameters due to insufficient input validation and output escaping. An unauthenticated attacker can inject arbitrary script into content that executes when a victim views an affected page.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References