The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ays_quick_start() and add_question_rows() functions in all versions up to, and including, 6.5.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary quizzes.
References
Configurations
History
14 Feb 2024, 18:39
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-862 | |
First Time |
Ays-pro quiz Maker
Ays-pro |
|
CPE | cpe:2.3:a:ays-pro:quiz_maker:*:*:*:*:*:wordpress:*:* | |
References | () https://plugins.trac.wordpress.org/changeset/3032035/quiz-maker/tags/6.5.2.5/admin/class-quiz-maker-admin.php?old=3030468&old_path=quiz-maker%2Ftags%2F6.5.2.4%2Fadmin%2Fclass-quiz-maker-admin.php - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/7ba2b270-5f02-4cd8-8a22-1723c3873d67?source=cve - Third Party Advisory |
07 Feb 2024, 13:41
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
07 Feb 2024, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-07 08:15
Updated : 2024-02-14 18:39
NVD link : CVE-2024-1078
Mitre link : CVE-2024-1078
CVE.ORG link : CVE-2024-1078
JSON object : View
Products Affected
ays-pro
- quiz_maker
CWE
CWE-862
Missing Authorization