Description
Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site scripting (XSS) vulnerability via multiple parameters due to insufficient input validation and output escaping. An unauthenticated attacker can inject arbitrary script into content that executes when a victim views an affected page.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
Any version before 19.6.25
Timeline
| 2019-09-16: | Vulnerability was publicly disclosed |
References
web.archive.org/...l-survey-form-quiz-maker-by-opinionstage/
wpscan.com/...rability/4ed1edd6-3813-44a3-bee7-f07c1774b679/
wpscan.com/...rability/4ed1edd6-3813-44a3-bee7-f07c1774b679/
www.wordfence.com/...thenticated-stored-cross-site-scripting
www.acunetix.com/...inionstage-cross-site-scripting-19-6-24/
wordpress.org/plugins/social-polls-by-opinionstage/
plugins.trac.wordpress.org/...0/social-polls-by-opinionstage
web.archive.org/...l-survey-form-quiz-maker-by-opinionstage/
www.vulncheck.com/...aker-plugin-by-opinion-stage-stored-xss