Lucene search

K
wpvulndbWpvulndbWPVDB-ID:2DC02E5C-1C89-4053-A6A7-29EE7B996183
HistoryMay 15, 2023 - 12:00 a.m.

Quiz Maker < 6.4.2.7 - Reflected XSS

2023-05-1500:00:00
wpscan.com
4
plugin security
reflected xss
cross-site scripting
admin privilege

0.001 Low

EPSS

Percentile

24.8%

The plugin does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PoC

Make a logged in admin open the URL below (other URL are also affected) https://example.com/wp-admin/admin.php?page=quiz-maker-settings&amp;ays;_quiz_tab=" accesskey=X onclick=alert(/XSS/)// The XSS will be triggered when pressing ALT+SHIFT+X on Windows and CTRL+ALT+X on OS X

CPENameOperatorVersion
quiz-makerlt6.4.2.7

0.001 Low

EPSS

Percentile

24.8%

Related for WPVDB-ID:2DC02E5C-1C89-4053-A6A7-29EE7B996183