← Retour aux CVEs
CVE-2019-25297
N/ADescription
Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site scripting (XSS) vulnerability via multiple parameters due to insufficient input validation and output escaping. An unauthenticated attacker can inject arbitrary script into content that executes when a victim views an affected page.
Details CVE
Score CVSS v3.1N/A
Publie1/16/2026
Derniere modification1/26/2026
Sourcenvd
Observations honeypot0
Faiblesses (CWE)
CWE-79
References
https://plugins.trac.wordpress.org/changeset/2158590/social-polls-by-opinionstage(disclosure@vulncheck.com)
https://web.archive.org/web/20191020011448/https://www.pluginvulnerabilities.com/2019/09/16/hackers-may-already-be-targeting-this-persistent-xss-vulnerability-in-poll-survey-form-quiz-maker-by-opinionstage/(disclosure@vulncheck.com)
https://wordpress.org/plugins/social-polls-by-opinionstage/(disclosure@vulncheck.com)
https://wpscan.com/vulnerability/4ed1edd6-3813-44a3-bee7-f07c1774b679/(disclosure@vulncheck.com)
https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-poll-survey-form-quiz-maker-by-opinionstage-cross-site-scripting-19-6-24/(disclosure@vulncheck.com)
https://www.vulncheck.com/advisories/poll-survey-and-quiz-maker-plugin-by-opinion-stage-stored-xss(disclosure@vulncheck.com)
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/social-polls-by-opinionstage/poll-survey-quiz-maker-plugin-by-opinion-stage-19625-unauthenticated-stored-cross-site-scripting(disclosure@vulncheck.com)
https://web.archive.org/web/20191020011448/https://www.pluginvulnerabilities.com/2019/09/16/hackers-may-already-be-targeting-this-persistent-xss-vulnerability-in-poll-survey-form-quiz-maker-by-opinionstage/(134c704f-9b21-4f2e-91b3-4a467353bcc0)
https://wpscan.com/vulnerability/4ed1edd6-3813-44a3-bee7-f07c1774b679/(134c704f-9b21-4f2e-91b3-4a467353bcc0)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.