plugin

Ari Stream Quiz Vulnerabilities

7 known security issues reported for the Ari Stream Quiz WordPress plugin. Most recent disclosed Dec 29, 2023.

1 high 6 medium

Running Ari Stream Quiz on your site? Check whether your installed version is affected.

Scan your site free

ARI Stream Quiz <= 1.3.0 - Authenticated (Contributor+) PHP Object Injection

high

The ARI Stream Quiz – WordPress Quizzes Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor access or higher to inject a PHP Object. No POP chain is pre...

CVSS:
8.8
Affected:
up to 1.3.0
Fixed in:
1.3.1
Disclosed:
Dec 29, 2023

CVE-2023-52182 on NVD →

ARI Stream Quiz <= 1.2.32 - Cross-Site Request Forgery

medium

The ARI Stream Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.32. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform unauthorized actions against classes and quizzes via a forged request grant...

CVSS:
5.4
Affected:
up to 1.2.32
Fixed in:
1.3.0
Disclosed:
Dec 27, 2023

CVE-2023-51487 on NVD →

ARI Stream Quiz <= 1.2.32 - Cross-Site Request Forgery

medium

The ARI Stream Quiz – WordPress Quizzes Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.32. This is due to missing or incorrect nonce validation on several functions related to quiz handling. This makes it possible for unauthenticated attackers to modif...

CVSS:
4.3
Affected:
up to 1.2.32
Fixed in:
1.3.0
Disclosed:
Nov 21, 2023

ARI Stream Quiz <= 1.2.32 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The ARI Stream Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...

CVSS:
6.4
Affected:
up to 1.2.32
Fixed in:
1.3.0
Disclosed:
Nov 16, 2023

CVE-2023-47835 on NVD →

ARI Stream Quiz <= 1.2.32 - Cross-Site Request Forgery

medium

The ARI Stream Quiz – WordPress Quizzes Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.32. This is due to missing nonce validation on several execute() functions found in various files. This makes it possible for unauthenticated attackers to copy, dele...

CVSS:
4.3
Affected:
up to 1.2.32
Fixed in:
1.3.0
Disclosed:
Nov 14, 2023

ARI Stream Quiz <= 1.3.2 - Authenticated(Contributor+) Content Injection

medium

The ARI Stream Quiz – WordPress Quizzes Builder plugin for WordPress is vulnerable to content injection due to improper capability checks on the quiz editing functionality in all versions up to, and including, 1.3.2. This makes it possible for authenticated attackers, with contributor access and above, to publish quizz...

CVSS:
4.3
Affected:
up to 1.3.2
Fixed in:
1.3.3
Disclosed:
Nov 7, 2023

CVE-2023-47513 on NVD →

ARI Stream Quiz – WordPress Quizzes Builder <= 1.2.26 - Reflected Cross-Site Scripting

medium

The ARI Stream Quiz – WordPress Quizzes Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msg' parameter in versions up to, and including, 1.2.26 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...

CVSS:
6.1
Affected:
up to 1.2.26
Fixed in:
1.2.27
Disclosed:
Feb 17, 2022

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database