CVE-2025-46482: WordPress WP Quiz plugin <= 2.0.10 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyThemeShop WP Quiz allows Stored XSS.This issue affects WP Quiz: from n/a through 2.0.10.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyThemeShop WP Quiz wp-quiz allows Stored XSS.This issue affects WP Quiz: from n/a through <= 2.0.10.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46482?
CVE-2025-46482 has a high severity level as it allows stored cross-site scripting (XSS) vulnerabilities in WP Quiz versions up to 2.0.10.
How do I fix CVE-2025-46482?
To fix CVE-2025-46482, you should update WP Quiz to version 2.0.11 or later where the vulnerability is patched.
What impact does CVE-2025-46482 have on my website?
CVE-2025-46482 can allow attackers to inject malicious scripts into web pages viewed by users, potentially compromising user data and site integrity.
Which versions of WP Quiz are affected by CVE-2025-46482?
CVE-2025-46482 affects all versions of WP Quiz from its initial release up to and including version 2.0.10.
Is CVE-2025-46482 already being exploited in the wild?
As of now, there have been no confirmed reports of exploitation of CVE-2025-46482 in the wild, but it is advisable to address the vulnerability promptly.