Lucene search

K
wpvulndbWpvulndbWPVDB-ID:4CE7AB1B-BBFF-4F1A-ABD8-3284CCA1A881
HistoryFeb 06, 2024 - 12:00 a.m.

Quiz Maker < 6.5.2.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Creation & Modification

2024-02-0600:00:00
wpscan.com
5
wordpress
quiz maker
vulnerability
unauthorized access
data modification
capability check

6.8 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

14.0%

Description The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ays_quick_start() and add_question_rows() functions in all versions up to, and including, 6.5.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary quizzes.

CPENameOperatorVersion
eq6.5.2.5

6.8 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

14.0%

Related for WPVDB-ID:4CE7AB1B-BBFF-4F1A-ABD8-3284CCA1A881