WordPress · Watu Quiz · CVE-2024-2640
**Name of the Vulnerable Software and Affected Versions**
Watu Quiz WordPress plugin versions prior to 3.4.1.2
**Description**
The issue allows users, such as authors authorized by admins, to perform Stored Cross-Site Scripting attacks, even when the unfiltered html capability is disallowed, due to the plugin not sanitizing and escaping some of its settings.
**Recommendations**
For versions prior to 3.4.1.2, update to version 3.4.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's settings to minimize the risk of exploitation.