CVE-2025-6174
WordPress Qwizcards <= 3.9.4 - Reflected XSS
Record summary
CVE-2025-6174 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The Qwizcards | online quizzes and flashcards WordPress plugin through 3.9.4 does not sanitise and escape the "_stylesheet" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or any other user.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 27, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 23, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Qwizcards | online quizzes and flashcardsBrowse Dan Kirshner / Qwizcards | online quizzes and flashcards | VulnCheck | Version data not supplied | |
Qwizcards | online quizzes and flashcardsDefault status: affected | CVE List | Through 3.9.4 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Qwizcards < 3.95 - Cross-Site Scripting (Reflected)CVSS 6.1
The WordPress Qwizcards plugin before version 3.95 does not sanitise and escape the "theme_stylesheet" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting vulnerability.
Impact
Attackers can execute scripts in the context of high privilege users, potentially leading to account compromise or session hijacking.
Remediation
Update to the latest version beyond 3.9.4.
Source: ProjectDiscovery