PT-2024-16909 · WordPress · Ai Quiz | Quiz Maker
Dale Mavers
+1
·
Published
2024-12-06
·
Updated
2024-12-11
·
CVE-2024-11323
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AI Quiz | Quiz Maker plugin for WordPress versions up to, and including, 1.1
Description
The issue allows unauthorized modification of data, leading to privilege escalation due to a missing capability check on the
ai quiz update style() function. This enables authenticated attackers with Subscriber-level access and above to update arbitrary options on the WordPress site, potentially gaining administrative user access.Recommendations
For AI Quiz | Quiz Maker plugin for WordPress versions up to, and including, 1.1, update the plugin to a version that includes the necessary capability checks to prevent unauthorized data modification.
As a temporary workaround, consider disabling the
ai quiz update style() function until a patch is available.
Restrict access to the plugin's functionality to minimize the risk of exploitation.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ai Quiz | Quiz Maker