Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown

CVE-2024-22027

Disclosure Date: January 12, 2024 (last updated January 19, 2024)
Improper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a remote authenticated attacker to perform a Denial of Service (DoS) attack against external services.
Attacker Value
Unknown

CVE-2023-6166

Disclosure Date: December 26, 2023 (last updated January 03, 2024)
The Quiz Maker WordPress plugin before 6.4.9.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting
Attacker Value
Unknown

CVE-2023-6155

Disclosure Date: December 26, 2023 (last updated January 03, 2024)
The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticated attacker to perform a search for users of the system, ultimately leaking user email addresses.
Attacker Value
Unknown

CVE-2023-36522

Disclosure Date: July 11, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in WePupil Quiz Expert plugin <= 1.5.0 versions.
Attacker Value
Unknown

CVE-2023-2571

Disclosure Date: June 05, 2023 (last updated October 08, 2023)
The Quiz Maker WordPress plugin before 6.4.2.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Attacker Value
Unknown

CVE-2021-24456

Disclosure Date: August 02, 2021 (last updated February 23, 2025)
The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL statements, leading to SQL injection issues in the admin dashboard