Description
Cross-Site Request Forgery (CSRF) vulnerability in CyrilG Fyrebox Quizzes fyrebox-shortcode allows Stored XSS.This issue affects Fyrebox Quizzes: from n/a through <= 3.1.
Published: 2025-02-07
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Cross‑Site Request Forgery flaw in the CyrilG Fyrebox Quizzes "fyrebox-shortcode" allows an attacker to submit a forged request that stores malicious script code in the site database. The injected script can then be rendered by browsers visiting the site, giving the attacker the ability to execute arbitrary JavaScript in the context of site visitors. This vulnerability combines CSRF (CWE‑352) with Stored XSS and can lead to theft of user credentials, defacement, or other actions carried out in the victim’s browser. The effect is not limited to a single user; any visitor who loads the affected page after the script is stored will be impacted.

Affected Systems

The Fyrebox Quizzes plugin by CyrilG is affected for all releases through version 3.1. The vulnerability was identified as present in all builds from the earliest available release (no starting version specified) up to and including 3.1. Users running any of these versions are exposed.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity assessment. The EPSS score of less than 1% suggests a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, implying no known exploitation in the wild at the time of analysis. The likely attack vector is through a CSRF attack, meaning the malicious request can be transmitted by tricking an authenticated user into visiting a crafted URL or loading a malicious page. An attacker would need to compromise or spoof a user’s session, but the CSRF nature lowers the barrier to that engagement, making the exploit potentially feasible in many environments.

Generated by OpenCVE AI on May 2, 2026 at 04:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Fyrebox Quizzes plugin to the latest version (greater than 3.1).
  • If an upgrade is not immediately possible, remove or disable the plugin to prevent further exploitation.
  • Delete any stored malicious script entries from the database while a patch is applied.

Generated by OpenCVE AI on May 2, 2026 at 04:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-4044 Cross-Site Request Forgery (CSRF) vulnerability in CyrilG Fyrebox Quizzes allows Stored XSS. This issue affects Fyrebox Quizzes: from n/a through 2.7.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in CyrilG Fyrebox Quizzes allows Stored XSS. This issue affects Fyrebox Quizzes: from n/a through 2.7. Cross-Site Request Forgery (CSRF) vulnerability in CyrilG Fyrebox Quizzes fyrebox-shortcode allows Stored XSS.This issue affects Fyrebox Quizzes: from n/a through <= 3.1.
Title WordPress Fyrebox Quizzes plugin <= 2.7 - CSRF to Stored XSS vulnerability WordPress Fyrebox Quizzes plugin <= 3.1 - CSRF to Stored XSS vulnerability
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 12 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Feb 2025 10:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in CyrilG Fyrebox Quizzes allows Stored XSS. This issue affects Fyrebox Quizzes: from n/a through 2.7.
Title WordPress Fyrebox Quizzes plugin <= 2.7 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:35.895Z

Reserved: 2025-02-03T13:34:51.002Z

Link: CVE-2025-25125

cve-icon Vulnrichment

Updated: 2025-02-12T20:46:18.643Z

cve-icon NVD

Status : Deferred

Published: 2025-02-07T10:15:17.813

Modified: 2026-04-23T15:25:39.417

Link: CVE-2025-25125

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T04:45:34Z

Weaknesses