Lucene search

K
wpvulndbWpvulndbWPVDB-ID:C5EEAF91-8E6D-4DC6-8FE6-41A0B7D0DFDD
HistoryFeb 06, 2024 - 12:00 a.m.

Quiz Maker < 6.5.2.5 - Missing Authorization to Unauthenticated Quiz Data Retrieval

2024-02-0600:00:00
wpscan.com
5
wordpress
vulnerability
data access

7.1 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

20.5%

Description The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_show_results() function in all versions up to, and including, 6.5.2.4. This makes it possible for unauthenticated attackers to fetch arbitrary quiz results which can contain PII.

CPENameOperatorVersion
eq6.5.2.5

7.1 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

20.5%

Related for WPVDB-ID:C5EEAF91-8E6D-4DC6-8FE6-41A0B7D0DFDD