Threats Tagged 'cve-2025-14579'
View all threats tagged with 'cve-2025-14579'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-14579'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2025-14579 is a medium severity Stored Cross-Site Scripting (XSS) vulnerability in the Quiz Maker WordPress plugin versions before 6.7.0.89. It arises because certain plugin settings are not properly sanitized or escaped, allowing high privilege users such as administrators to inject malicious scripts. This vulnerability can be exploited even when the unfiltered_html capability is disabled, such as in multisite WordPress setups. Exploitation requires high privileges and user interaction, and it can lead to limited confidentiality and integrity impacts, but no direct availability impact. No known exploits are currently reported in the wild. European organizations using affected versions of Quiz Maker, especially those with multisite WordPress deployments, should prioritize patching or mitigating this issue to prevent potential stored XSS attacks that could compromise administrative sessions or site content. Join the discussion | CVE Database V5 | 01/12/2026, 06:00:10 UTC Added: 01/12/2026, 06:08:45 UTC |
Showing 1 to 1 of 1 result