Record summary

CVE-2025-6174 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Qwizcards | online quizzes and flashcards WordPress plugin through 3.9.4 does not sanitise and escape the "_stylesheet" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or any other user.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 27, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 23, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Qwizcards | online quizzes and flashcards

Default status: affected

CVE ListThrough 3.9.4affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Qwizcards < 3.95 - Cross-Site Scripting (Reflected)CVSS 6.1

The WordPress Qwizcards plugin before version 3.95 does not sanitise and escape the "theme_stylesheet" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting vulnerability.

Impact

Attackers can execute scripts in the context of high privilege users, potentially leading to account compromise or session hijacking.

Remediation

Update to the latest version beyond 3.9.4.

WeaknessesCWE-79
Authors0x_Akoko
Template tagscvecve2025qwizcardswordpresswp-pluginxssunauthvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Source: ProjectDiscovery

References

2