VYPR
Medium severity6.4NVD Advisory· Published Oct 31, 2025· Updated Apr 15, 2026

CVE-2025-11806

CVE-2025-11806

Description

The Qzzr Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qzzr' shortcode in all versions up to, and including, 1.0.1. This is due to insufficient input sanitization and output escaping on the 'quiz' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Qzzr Shortcode Plugin for WordPress allows contributor-level users to inject arbitrary scripts via the 'quiz' attribute.

The Qzzr Shortcode Plugin for WordPress (versions up to 1.0.1) is vulnerable to Stored Cross-Site Scripting (XSS). The vulnerability originates from insufficient input sanitization and output escaping on the 'quiz' attribute within the 'qzzr' shortcode. This allows attackers to inject arbitrary web scripts that become stored on the server and execute when a user visits the affected page [1].

Exploitation requires authenticated access with contributor-level privileges or higher. The attacker crafts a post or page containing the malicious shortcode, which then appears to any visitor. No additional network access is needed beyond standard WordPress functionality, and the stored script runs in the context of the victim's browser session [1].

Successful exploitation leads to arbitrary script execution in the browser of users accessing the injected page. This can result in session hijacking, defacement, or redirection to malicious sites. The impact is limited by the requirement for an authenticated account with contributor capabilities [1].

The plugin has been closed on the WordPress plugin directory as of October 24, 2025, and is no longer available for download. Users should remove the plugin from their sites immediately, as no patched version exists [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.