PT-2024-16548 · WordPress · Quiz Maker

Lucio Sá

·

Published

2024-02-07

·

Updated

2024-02-22

·

CVE-2024-1079

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Quiz Maker plugin for WordPress versions up to, and including, 6.5.2.4
Description The issue arises from a missing capability check on the ays show results() function, allowing unauthenticated attackers to access arbitrary quiz results, which may contain personally identifiable information (PII).
Recommendations For versions up to, and including, 6.5.2.4, consider disabling the ays show results() function as a temporary workaround until a patch is available. Restrict access to quiz results to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-1079

Affected Products

Quiz Maker