PT-2023-32547 · WordPress · Quiz Maker

Krzysztof Zając

·

Published

2023-12-26

·

Updated

2024-09-12

·

CVE-2023-6155

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Quiz Maker WordPress plugin versions prior to 6.4.9.5
Description The issue allows an unauthenticated attacker to perform a search for users of the system, ultimately leaking user email addresses, due to inadequate authorization of the ays quiz author user search AJAX action.
Recommendations For versions prior to 6.4.9.5, update to version 6.4.9.5 or later to resolve the issue. As a temporary workaround, consider disabling the ays quiz author user search AJAX action until a patch is available. Restrict access to the vulnerable AJAX endpoint to minimize the risk of exploitation. Avoid using the ays quiz author user search action in the affected plugin until the issue is resolved.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2023-6155

Affected Products

Quiz Maker