CVE-2023-23985
- EPSS 0.08%
- Veröffentlicht 24.04.2024 11:15:46
- Zuletzt bearbeitet 31.12.2025 21:52:58
Missing Authorization vulnerability in Quiz Maker team Quiz Maker.This issue affects Quiz Maker: from n/a through 6.3.9.4.
CVE-2024-1079
- EPSS 0.33%
- Veröffentlicht 07.02.2024 08:15:43
- Zuletzt bearbeitet 21.11.2024 08:49:45
The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_show_results() function in all versions up to, and including, 6.5.2.4. This makes it possible for unauthenticated attackers ...
CVE-2024-1078
- EPSS 0.12%
- Veröffentlicht 07.02.2024 08:15:42
- Zuletzt bearbeitet 21.11.2024 08:49:44
The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ays_quick_start() and add_question_rows() functions in all versions up to, and including, 6.5.2.4. This makes it possible ...
CVE-2024-22027
- EPSS 0.51%
- Veröffentlicht 12.01.2024 07:15:12
- Zuletzt bearbeitet 05.06.2025 19:15:25
Improper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a remote authenticated attacker to perform a Denial of Service (DoS) attack against external services.
CVE-2023-6166
- EPSS 0.12%
- Veröffentlicht 26.12.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:43:17
The Quiz Maker WordPress plugin before 6.4.9.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting
CVE-2023-6155
- EPSS 0.21%
- Veröffentlicht 26.12.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:43:15
The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticated attacker to perform a search for users of the system, ultimately leaking user email addresses.
CVE-2023-2571
- EPSS 0.21%
- Veröffentlicht 05.06.2023 14:15:10
- Zuletzt bearbeitet 08.01.2025 16:15:28
The Quiz Maker WordPress plugin before 6.4.2.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2021-24456
- EPSS 0.53%
- Veröffentlicht 02.08.2021 11:15:09
- Zuletzt bearbeitet 21.11.2024 05:53:06
The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL statements, leading to SQL injection issues in the admin dashboard