Qwizcards | online quizzes and flashcards

Qwizcards | online quizzes and flashcards has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2019 and 2025; all 3 are fixed as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Scripting, behind 3 of the records (100%).

Every one of the 3 issues recorded for Qwizcards | online quizzes and flashcards has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, one record each. Qwizcards | online quizzes and flashcards is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
5.9/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all Qwizcards | online quizzes and flashcards vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2025-6174

WordPress Qwizcards <= 3.94 - Reflected Cross-Site Scripting

Read the full analysis

Vulnerability Records

3 records
Plugin Profile
Latestv4.02

Qwizcards | online quizzes and flashcards

Dan Kirshner

Author

Dan Kirshner

5.0(11)
100/100
Last Updated
2026-08-06 (1mo ago)
Active Installs
200+
Downloads
69,774
Requires WP
0+
Requires PHP
0+
Tested up to
WP 7.0.4
Created
2014-08-01 (12y ago)

Online quizzes and flashcards for WordPress. Qwizcards lets you create fill-in-the-blank questions with “autocomplete” suggestion lists. You can include images, and labels that can be dragged-and-dropped to hot-spot targets on the images. Qwizcards includes progress and reporting features — students can log in when they take a quiz, and you can get score reports by student. See https://qwizcards.net An interactive what-you-see-is-what-you-get (WYSIWYG) “wizard” makes it easy to create quizzes and flashcard decks, and/or you can edit the shortcodes directly. Online demo: https://qwizcards.net/wizard In the WordPress Block Editor, open a Classic paragraph or block and click the “Q” icon to get started! (In either the “Block Editor” or the “Classic Editor” you may have to click the “Toolbar Toggle” icon to see the “Q” – it’s in the second row.)

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C