CVE-2019-25297

EXPLOITED

Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin ...

Title source: llm

Description

Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site scripting (XSS) vulnerability via multiple parameters due to insufficient input validation and output escaping. An unauthenticated attacker can inject arbitrary script into content that executes when a victim views an affected page.

Scores

EPSS 0.0004
EPSS Percentile 11.0%

Exploitation Intel

VulnCheck KEV 2019-09-16

Classification

CWE
CWE-79
Status draft

Timeline

Published Jan 16, 2026
Tracked Since Feb 18, 2026