CVE-2019-25297: Assaf Parag Poll, Survey & Quiz Maker Plugin By Opinion Stage

Medium severity, CVSS 5.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site scripting (XSS) vulnerability via multiple parameters due to insufficient input validation and output escaping. An unauthenticated attacker can inject arbitrary script into content that executes when a victim views an affected page.

Affected products

  • Assaf Parag Poll, Survey & Quiz Maker Plugin By Opinion Stage: before 19.6.25 (fixed in 19.6.25)

Published 2026-01-16. Last modified 2026-06-17.