The WordPress Qwizcards plugin before version 3.95 does not sanitise and escape the "theme_stylesheet" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting vulnerability.
id: CVE-2025-6174
info:
name: WordPress Qwizcards < 3.95 - Cross-Site Scripting (Reflected)
aut
...