PT-2024-16909 · WordPress · Ai Quiz | Quiz Maker

Dale Mavers

+1

·

Published

2024-12-06

·

Updated

2024-12-11

·

CVE-2024-11323

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AI Quiz | Quiz Maker plugin for WordPress versions up to, and including, 1.1
Description The issue allows unauthorized modification of data, leading to privilege escalation due to a missing capability check on the ai quiz update style() function. This enables authenticated attackers with Subscriber-level access and above to update arbitrary options on the WordPress site, potentially gaining administrative user access.
Recommendations For AI Quiz | Quiz Maker plugin for WordPress versions up to, and including, 1.1, update the plugin to a version that includes the necessary capability checks to prevent unauthorized data modification. As a temporary workaround, consider disabling the ai quiz update style() function until a patch is available. Restrict access to the plugin's functionality to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-11323

Affected Products

Ai Quiz | Quiz Maker