Skip to content

Known CVE

WordPress Qwizcards < 3.95 - Cross-Site Scripting (Reflected)

The WordPress Qwizcards plugin before version 3.95 does not sanitise and escape the "theme_stylesheet" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting vulnerability.

CVE-2025-6174

Medium2025CVSS 6.1CWE-79

cve2025 · qwizcards · wordpress · wp-plugin · xss · unauth · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website