Data Modification Vulnerability in Opinion Stage Poll, Survey & Quiz Maker Plugin for WordPress
CVE-2025-3880

4.3MEDIUM

What is CVE-2025-3880?

The Poll, Survey & Quiz Maker Plugin by Opinion Stage for WordPress is susceptible to unauthorized data modifications due to improper capability checks affecting numerous functions. This vulnerability permits authenticated users with Contributor-level access or higher to alter the email address linked to the account, resulting in disconnection of the plugin. Although previously generated content remains accessible, the ability to tamper with crucial account settings poses significant risks to users.

Affected Version(s)

Poll, Survey & Quiz Maker Plugin by Opinion Stage * <= 19.9.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Amin Beheshti
.
CVE-2025-3880 : Data Modification Vulnerability in Opinion Stage Poll, Survey & Quiz Maker Plugin for WordPress