CVE-2025-23724: WordPress University Quizzes Online plugin <= 1.4 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oleksandr87 University Quizzes Online university-quizzes-online allows Reflected XSS.This issue affects University Quizzes Online: from n/a through <= 1.4.
Security readout for executives and security teams
Plain-English summary
This CVE affects the WordPress University Quizzes Online plugin through version 1.4. A reflected cross-site scripting flaw could let an attacker make a victim’s browser run attacker-controlled script after user interaction. The sources do not identify active exploitation or a confirmed fixed version.
Executive priority
Treat as a high-priority WordPress plugin risk where the plugin is present. It is not a confirmed mass-exploitation issue from the provided evidence, but exposed sites should be inventoried and remediated promptly.
Technical view
CVE-2025-23724 is CWE-79 reflected XSS in oleksandr87 University Quizzes Online for WordPress, affecting versions through 1.4. CVSS 3.1 is 7.1 with network access, low complexity, no privileges, required user interaction, changed scope, and low confidentiality, integrity, and availability impact.
Likely exposure
Exposure is limited to WordPress sites with the University Quizzes Online plugin installed at version 1.4 or earlier. The provided sources do not state install prevalence, specific vulnerable parameters, or affected public routes.
Exploitation context
No active exploitation is supported by the provided sources, and the CVE is not marked KEV. Successful exploitation requires user interaction, consistent with reflected XSS, but the source bundle does not provide exploit maturity details.
Researcher notes
The public bundle confirms type, severity, affected range, and Patchstack reference, but lacks vulnerable parameter details, proof-of-concept status, and fixed-version information. Avoid assuming exploit availability or remediation beyond vendor guidance.
Mitigation direction
Inventory WordPress sites for the University Quizzes Online plugin.
Check vendor, WordPress, CVE, or Patchstack guidance for a fixed version.
Update the plugin if a maintained fixed release is available.
Disable or remove the plugin if no safe update is available.
Prioritize sites used by administrators, editors, or authenticated staff.
Validation and detection
Confirm whether the plugin package name university-quizzes-online is installed.
Record the installed plugin version and compare it with version 1.4 or earlier.
Review vendor or Patchstack advisories for updated remediation status.
Check whether plugin-facing quiz pages are publicly reachable.
Review security telemetry for suspicious reflected-XSS indicators without reproducing payloads.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-79: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-79 · source CWE mapping
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.