References https://nvd.nist.gov/vuln/detail/CVE-2025-6174 https://wpscan.com/vulnerability/ff827f67-712e-4ab6-b6aa-7f5e6ff1283a/ https://access.redhat.com/security/cve/cve-2025-6174 https://github.com/advisories/GHSA-m4x7-38rv-hjmc https://cve.imfht.com/detail/CVE-2025-6174?lang=en https://hackhalt.com/threat/cve-2025-6174/ https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/qwiz-online-quizzes-and-flashcards/wordpress-qwizcards-394-reflected-cross-site-scripting https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-6174.yaml https://patchstack.com/database/wordpress/plugin/qwiz-online-quizzes-and-flashcards/vulnerability/wordpress-wordpress-qwizcards-plugin-3-9-4-reflected-xss-vulnerability https://cve.imfht.com/poc_detail/733c88122cdd60930784f5b97835aaaf587cbfd2?lang=en
Related VulnerabilitiesPoCCVE-2026-0692: BlueSnap Payment Gateway for WooCommerce <=3.4.0 - IPN Authorization BypassPoCCVE-2026-40281: Gotenberg <= 8.30.1 - Remote Code ExecutionPoCCVE-2026-86242: Bifrost < 1.6.3 - Unauthenticated Remote Plugin URL FetchQAnything /api/local_doc_qa/upload_files 文件上传漏洞(CVE-2026-88533)Netbox-Docker /api/status/ 默认口令漏洞(CVE-2023-27573)PoCCVE-2025-11452: Asgaros Forum < 3.2.0 - SQL InjectionPoCCVE-2025-34033: Blue Angel Software Suite (5V Technologies) - OS Command InjectionPoCCVE-2025-62593: Ray < 2.52.0 - Remote Code ExecutionPoCCVE-2025-68273: Signal K Server <= 2.18.0 - Information DisclosurePoCCVE-2026-25703: NeuVector - Information DisclosurePoCCVE-2026-87902: WordPress Core - PHP Template Path TraversalPoCCVE-2026-89013: Dolibarr < 24.0.0 - Authorization Bypass via hashp ParameterPoCCVE-2026-89063: Bookly <=28.1 - IDOR Unauthenticated Sensitive Data Access