Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site scripting (XSS) vulnerability via multiple parameters due to insufficient input validation and output escaping. An unauthenticated attacker can inject arbitrary script into content that executes when a victim views an affected page.

Project Subscriptions

Vendors Products
Opinionstage Subscribe
Poll, Survey & Quiz Maker Subscribe
Wordpress Subscribe
Wordpress Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 19 Jan 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Opinionstage
Opinionstage poll, Survey & Quiz Maker
Wordpress
Wordpress wordpress
Vendors & Products Opinionstage
Opinionstage poll, Survey & Quiz Maker
Wordpress
Wordpress wordpress

Fri, 16 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 16 Jan 2026 20:30:00 +0000

Type Values Removed Values Added
Description Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site scripting (XSS) vulnerability via multiple parameters due to insufficient input validation and output escaping. An unauthenticated attacker can inject arbitrary script into content that executes when a victim views an affected page.
Title Poll, Survey & Quiz Maker Plugin by Opinion Stage < 19.6.25 Stored XSS
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-01-16T21:08:52.376Z

Reserved: 2026-01-16T19:19:40.819Z

Link: CVE-2019-25297

cve-icon Vulnrichment

Updated: 2026-01-16T20:58:48.707Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-16T21:15:49.930

Modified: 2026-01-26T15:05:39.840

Link: CVE-2019-25297

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-19T09:19:42Z

Weaknesses