References https://nvd.nist.gov/vuln/detail/CVE-2025-6174 https://wpscan.com/vulnerability/ff827f67-712e-4ab6-b6aa-7f5e6ff1283a/ https://access.redhat.com/security/cve/cve-2025-6174 https://github.com/advisories/GHSA-m4x7-38rv-hjmc https://cve.imfht.com/detail/CVE-2025-6174?lang=en https://hackhalt.com/threat/cve-2025-6174/ https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/qwiz-online-quizzes-and-flashcards/wordpress-qwizcards-394-reflected-cross-site-scripting https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-6174.yaml https://patchstack.com/database/wordpress/plugin/qwiz-online-quizzes-and-flashcards/vulnerability/wordpress-wordpress-qwizcards-plugin-3-9-4-reflected-xss-vulnerability https://cve.imfht.com/poc_detail/733c88122cdd60930784f5b97835aaaf587cbfd2?lang=en
Related VulnerabilitiesPoCCVE-2026-27960: OpenCTI < 6.9.13 - Authentication Bypass via User ImpersonationPoCCVE-2020-29134: TOTVS Fluig <= 1.7.0 - Arbitrary File ReadPoCCVE-2023-54391: Proxmox VE - Default Credentials with TFA BypassPoCCVE-2025-51683: mJobTime <= 15.7.2 - Unauthenticated Blind SQL Injection to RCEPoCCVE-2025-57231: Docmost 0.2.1-0.21.0 - Arbitrary File ReadPoCCVE-2026-19632: TranslatePress <= 3.3.1 - Unauthenticated Account TakeoverPoCCVE-2026-2113: tpadmin <= 1.3.12 - Remote Code ExecutionPoCCVE-2026-23693: ElementsKit Lite <3.7.9 - Unauthenticated Mailchimp ProxyPoCCVE-2026-28141: NextGEN Gallery <= 4.2.3 - Reflected Cross-Site ScriptingPoCCVE-2026-28411: WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract()PoCCVE-2026-29963: HSC MailInspector - Unauthenticated Arbitrary File ReadPoCCVE-2026-30849: MantisBT < 2.28.1 - SOAP API Authentication BypassPoCCVE-2026-34234: CtrlPanel <= 1.1.1 - Remote Code Execution