Chained Quiz <= 1.3.5 - Unauthenticated Insecure Direct Object Reference via Cookie
medium
The Chained Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference in version 1.3.4 and below via the quiz submission and completion mechanisms due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to hijack and modify other users' quiz attempts by...
- CVSS:
- 5.3
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.6
- Disclosed:
- Sep 17, 2025
CVE-2025-10493 on NVD →
Chained Quiz <= 1.3.2.9 - Authenticated (Admin+) Server-Side Request Forgery
medium
The Chained Quiz plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.2.9. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application which can be u...
- CVSS:
- 5.5
- Affected:
- up to 1.3.2.9
- Fixed in:
- 1.3.3
- Disclosed:
- Jan 24, 2025
CVE-2025-24701 on NVD →
Chained Quiz [chained-quiz] < 1.3.3
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Kiboko Labs Chained Quiz allows Server Side Request Forgery. This issue affects Chained Quiz: from n/a through 1.3.2.9.
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.3
- Disclosed:
- Jan 24, 2025
CVE-2025-24701 on NVD →
Chained Quiz [chained-quiz] < 1.3.2.9
unknown
[en] Missing Authorization vulnerability in Kiboko Labs Chained Quiz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chained Quiz: from n/a through 1.3.2.8.
- Affected:
- up to 1.3.2.9
- Fixed in:
- 1.3.2.9
- Disclosed:
- Nov 1, 2024
CVE-2024-37921 on NVD →
Chained Quiz [chained-quiz] < 1.3.2.9
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kiboko Labs Chained Quiz allows Stored XSS.This issue affects Chained Quiz: from n/a through 1.3.2.8.
- Affected:
- up to 1.3.2.9
- Fixed in:
- 1.3.2.9
- Disclosed:
- Jul 21, 2024
CVE-2024-37446 on NVD →
Chained Quiz <= 1.3.2.8 - Missing Authorization
medium
The Chained Quiz plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the finalize() function in all versions up to, and including, 1.3.2.8. This makes it possible for unauthenticated attackers to answer quizzes that require logging in.
- CVSS:
- 5.3
- Affected:
- up to 1.3.2.8
- Fixed in:
- 1.3.2.9
- Disclosed:
- Jul 9, 2024
CVE-2024-37921 on NVD →
Chained Quiz <= 1.3.2.8 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages...
- CVSS:
- 4.4
- Affected:
- up to 1.3.2.8
- Fixed in:
- 1.3.2.9
- Disclosed:
- Jun 28, 2024
CVE-2024-37446 on NVD →
Chained Quiz [chained-quiz] < 1.3.2.6
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Chained Quiz plugin <= 1.3.2.5 versions.
- Affected:
- up to 1.3.2.6
- Fixed in:
- 1.3.2.6
- Disclosed:
- Apr 7, 2023
CVE-2023-25027 on NVD →
Chained Quiz <= 1.3.2.5 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions, to inject arbitrary web scripts in pages that...
- CVSS:
- 5.5
- Affected:
- up to 1.3.2.5
- Fixed in:
- 1.3.2.6
- Disclosed:
- Feb 6, 2023
CVE-2023-25027 on NVD →
Chained Quiz <= 1.3.2 - Reflected Cross-Site Scripting via datef
medium
The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'datef' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...
- CVSS:
- 6.1
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.2.1
- Disclosed:
- Dec 2, 2022
CVE-2022-4208 on NVD →
Chained Quiz <= 1.3.2 - Reflected Cross-Site Scripting via emailf
medium
The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'emailf' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...
- CVSS:
- 6.1
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.2.1
- Disclosed:
- Dec 2, 2022
CVE-2022-4211 on NVD →
Chained Quiz <= 1.3.2.3 - Reflected Cross-Site Scripting via ip
medium
The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ip' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...
- CVSS:
- 6.1
- Affected:
- up to 1.3.2.3
- Fixed in:
- 1.3.2.4
- Disclosed:
- Dec 2, 2022
CVE-2022-4214 on NVD →
Chained Quiz <= 1.3.2.2 - Reflected Cross-Site Scripting via dn
medium
The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dn' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...
- CVSS:
- 6.1
- Affected:
- up to 1.3.2.2
- Fixed in:
- 1.3.2.3
- Disclosed:
- Dec 2, 2022
CVE-2022-4213 on NVD →
Chained Quiz <= 1.3.2 - Reflected Cross-Site Scripting via dnf
medium
The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dnf' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc...
- CVSS:
- 6.1
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.2.1
- Disclosed:
- Dec 2, 2022
CVE-2022-4210 on NVD →
Chained Quiz <= 1.3.2 - Reflected Cross-Site Scripting via ipf
medium
The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ipf' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc...
- CVSS:
- 6.1
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.2.1
- Disclosed:
- Dec 2, 2022
CVE-2022-4212 on NVD →
Chained Quiz <= 1.3.2.3 - Reflected Cross-Site Scripting via date
medium
The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...
- CVSS:
- 6.1
- Affected:
- up to 1.3.2.3
- Fixed in:
- 1.3.2.4
- Disclosed:
- Dec 2, 2022
CVE-2022-4215 on NVD →
Chained Quiz <= 1.3.2 - Reflected Cross-Site Scripting via pointsf
medium
The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pointsf' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary we...
- CVSS:
- 6.1
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.2.1
- Disclosed:
- Dec 2, 2022
CVE-2022-4209 on NVD →
Chained Quiz <= 1.3.2.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Facebook App ID
medium
The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'facebook_appid' parameter in versions up to, and including, 1.3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrar...
- CVSS:
- 5.5
- Affected:
- up to 1.3.2.2
- Fixed in:
- 1.3.2.3
- Disclosed:
- Dec 2, 2022
CVE-2022-4216 on NVD →
Chained Quiz <= 1.3.2.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Mailchimp API Key
medium
The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key' parameter in versions up to, and including, 1.3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrary web s...
- CVSS:
- 5.5
- Affected:
- up to 1.3.2.2
- Fixed in:
- 1.3.2.3
- Disclosed:
- Dec 2, 2022
CVE-2022-4217 on NVD →
Chained Quiz <= 1.3.2.4 - Cross-Site Request Forgery to Question Deletion
medium
The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4. This is due to missing nonce validation on the list_questions() function. This makes it possible for unauthenticated attackers to delete questions from quizzes via a forged request granted they c...
- CVSS:
- 5.4
- Affected:
- up to 1.3.2.4
- Fixed in:
- 1.3.2.5
- Disclosed:
- Dec 2, 2022
CVE-2022-4220 on NVD →
Chained Quiz <= 1.3.2.4 - Cross-Site Request Forgery to Submitted Response Deletion
medium
The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4. This is due to missing nonce validation on the manage() function. This makes it possible for unauthenticated attackers to delete submitted quiz responses via a forged request granted they can tri...
- CVSS:
- 5.4
- Affected:
- up to 1.3.2.4
- Fixed in:
- 1.3.2.5
- Disclosed:
- Dec 2, 2022
CVE-2022-4219 on NVD →
Chained Quiz <= 1.3.2.4 - Cross-Site Request Forgery to Arbitrary Quiz Deletion and Copying
medium
The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4. This is due to missing nonce validation on the list_quizzes() function. This makes it possible for unauthenticated attackers to delete quizzes and copy quizzes via a forged request granted they c...
- CVSS:
- 5.4
- Affected:
- up to 1.3.2.4
- Fixed in:
- 1.3.2.5
- Disclosed:
- Dec 2, 2022
CVE-2022-4218 on NVD →
Chained Quiz [chained-quiz] < 1.3.2.5
unknown
[en] The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4. This is due to missing nonce validation on the manage() function. This makes it possible for unauthenticated attackers to delete submitted quiz responses via a forged request granted they ca...
- Affected:
- up to 1.3.2.5
- Fixed in:
- 1.3.2.5
- Disclosed:
- Dec 2, 2022
CVE-2022-4219 on NVD →
Chained Quiz [chained-quiz] < 1.3.2.1
unknown
[en] The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'datef' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...
- Affected:
- up to 1.3.2.1
- Fixed in:
- 1.3.2.1
- Disclosed:
- Dec 2, 2022
CVE-2022-4208 on NVD →
Chained Quiz [chained-quiz] < 1.3.2.1
unknown
[en] The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pointsf' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra...
- Affected:
- up to 1.3.2.1
- Fixed in:
- 1.3.2.1
- Disclosed:
- Dec 2, 2022
CVE-2022-4209 on NVD →
Chained Quiz [chained-quiz] < 1.3.2.1
unknown
[en] The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dnf' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w...
- Affected:
- up to 1.3.2.1
- Fixed in:
- 1.3.2.1
- Disclosed:
- Dec 2, 2022
CVE-2022-4210 on NVD →
Chained Quiz [chained-quiz] < 1.3.2.1
unknown
[en] The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'emailf' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...
- Affected:
- up to 1.3.2.1
- Fixed in:
- 1.3.2.1
- Disclosed:
- Dec 2, 2022
CVE-2022-4211 on NVD →
Chained Quiz [chained-quiz] < 1.3.2.3
unknown
[en] The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ipf' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w...
- Affected:
- up to 1.3.2.3
- Fixed in:
- 1.3.2.3
- Disclosed:
- Dec 2, 2022
CVE-2022-4212 on NVD →
Chained Quiz [chained-quiz] < 1.3.2.3
unknown
[en] The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dn' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...
- Affected:
- up to 1.3.2.3
- Fixed in:
- 1.3.2.3
- Disclosed:
- Dec 2, 2022
CVE-2022-4213 on NVD →
Chained Quiz [chained-quiz] < 1.3.2.4
unknown
[en] The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ip' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...
- Affected:
- up to 1.3.2.4
- Fixed in:
- 1.3.2.4
- Disclosed:
- Dec 2, 2022
CVE-2022-4214 on NVD →
Chained Quiz [chained-quiz] < 1.3.2.4
unknown
[en] The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...
- Affected:
- up to 1.3.2.4
- Fixed in:
- 1.3.2.4
- Disclosed:
- Dec 2, 2022
CVE-2022-4215 on NVD →
Chained Quiz [chained-quiz] < 1.3.2.3
unknown
[en] The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'facebook_appid' parameter in versions up to, and including, 1.3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arb...
- Affected:
- up to 1.3.2.3
- Fixed in:
- 1.3.2.3
- Disclosed:
- Dec 2, 2022
CVE-2022-4216 on NVD →
Chained Quiz [chained-quiz] < 1.3.2.3
unknown
[en] The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key' parameter in versions up to, and including, 1.3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrary...
- Affected:
- up to 1.3.2.3
- Fixed in:
- 1.3.2.3
- Disclosed:
- Dec 2, 2022
CVE-2022-4217 on NVD →
Chained Quiz [chained-quiz] < 1.3.2.5
unknown
[en] The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4. This is due to missing nonce validation on the list_quizzes() function. This makes it possible for unauthenticated attackers to delete quizzes and copy quizzes via a forged request granted t...
- Affected:
- up to 1.3.2.5
- Fixed in:
- 1.3.2.5
- Disclosed:
- Dec 2, 2022
CVE-2022-4218 on NVD →
Chained Quiz [chained-quiz] < 1.3.2.5
unknown
[en] The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4. This is due to missing nonce validation on the list_questions() function. This makes it possible for unauthenticated attackers to delete questions from quizzes via a forged request granted t...
- Affected:
- up to 1.3.2.5
- Fixed in:
- 1.3.2.5
- Disclosed:
- Dec 2, 2022
CVE-2022-4220 on NVD →
Chained Quiz [chained-quiz] < 1.2.7.2
unknown
[en] The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings.
- Affected:
- up to 1.2.7.2
- Fixed in:
- 1.2.7.2
- Disclosed:
- Oct 11, 2021
CVE-2021-24690 on NVD →
Chained Quiz < 1.2.7.2 - Cross-Site Scripting
medium
The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings.
- CVSS:
- 5.4
- Affected:
- up to 1.2.7.2
- Fixed in:
- 1.2.7.2
- Disclosed:
- Sep 7, 2021
CVE-2021-24690 on NVD →
Chained Quiz [chained-quiz] < 1.0.9
unknown
[en] controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote unauthenticated users to execute arbitrary SQL commands via the 'answer' and 'answers' parameters.
- Affected:
- up to 1.0.9
- Fixed in:
- 1.0.9
- Disclosed:
- Mar 10, 2020
CVE-2018-14502 on NVD →
Chained Quiz <= 1.1.9 -Stored Cross-Site Scripting
medium
The Chained Quiz for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘chained_admin_subject', 'chained_user_subject', 'chained_sender_name', 'chained_sender_email' and 'go_ahead_value' values in versions up to, and including, 1.1.9.0 due to insufficient input sanitization and output escaping. This makes...
- CVSS:
- 6.4
- Affected:
- up to 1.1.9
- Fixed in:
- 1.1.9.1
- Disclosed:
- Feb 21, 2020
Chained Quiz [chained-quiz] < 1.1.9.1
unknown
The Chained Quiz for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘chained_admin_subject', 'chained_user_subject', 'chained_sender_name', 'chained_sender_email' and 'go_ahead_value' values in versions up to, and including, 1.1.9.0 due to insufficient input sanitization and output escaping. This makes...
- Affected:
- up to 1.1.9.1
- Fixed in:
- 1.1.9.1
- Disclosed:
- Feb 21, 2020
Chained Quiz [chained-quiz] < 1.1.9.1
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by khoabda in WordPress Chained Quiz plugin (versions <= 1.1.9).
- Affected:
- up to 1.1.9.1
- Fixed in:
- 1.1.9.1
- Disclosed:
- Feb 21, 2020
Chained Quiz [chained-quiz] < 1.1.8.2
unknown
[en] The chained-quiz plugin 1.1.8.1 for WordPress has reflected XSS via the wp-admin/admin-ajax.php total_questions parameter.
- Affected:
- up to 1.1.8.2
- Fixed in:
- 1.1.8.2
- Disclosed:
- Jan 17, 2020
CVE-2020-7104 on NVD →
Chained Quiz <= 1.1.8.1 - Reflected Cross-Site Scripting
medium
The chained-quiz plugin 1.1.8.1 for WordPress has reflected XSS via the wp-admin/admin-ajax.php total_questions parameter.
- CVSS:
- 6.1
- Affected:
- up to 1.1.8.2
- Fixed in:
- 1.1.8.2
- Disclosed:
- Jan 16, 2020
CVE-2020-7104 on NVD →
Chained Quiz [chained-quiz] < 1.0
unknown
[en] The chained-quiz plugin before 1.0 for WordPress has multiple XSS issues.
- Affected:
- up to 1.0
- Fixed in:
- 1.0
- Disclosed:
- Aug 20, 2019
CVE-2016-10892 on NVD →
Chained Quiz <= 1.0.8.2 - Unauthenticated SQL Injection
critical
controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote unauthenticated users to execute arbitrary SQL commands via the 'answer' and 'answers' parameters.
- CVSS:
- 9.8
- Affected:
- up to 1.0.9
- Fixed in:
- 1.0.9
- Disclosed:
- Aug 16, 2018
CVE-2018-14502 on NVD →
Chained Quiz Plugin < 1.0 - Cross-Site Scripting
medium
The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 0.9.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if t...
- CVSS:
- 6.1
- Affected:
- up to 1.0
- Fixed in:
- 1.0
- Disclosed:
- Jan 12, 2017
CVE-2016-10892 on NVD →
Chained Quiz [chained-quiz] < 1.0
unknown
WordPress Chained Quiz plugin is prone to a cross site scripting vulnerability. Some PHP variables such as $vars[‘question’]” and “$vars[‘qtype’]” are not sanitized.
Update the plugin.
- Affected:
- up to 1.0
- Fixed in:
- 1.0
- Disclosed:
- Jan 12, 2017
Chained Quiz <= 0.9.8 - Cross-Site Scripting
medium
The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.9.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.4
- Affected:
- up to 0.9.8
- Fixed in:
- 0.9.9
- Disclosed:
- Dec 21, 2016
Chained Quiz [chained-quiz] < 0.9.9
unknown
The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.9.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 0.9.9
- Fixed in:
- 0.9.9
- Disclosed:
- Dec 21, 2016
Chained Quiz [chained-quiz] < 0.9.9
unknown
This plugin is prone to a cross site scripting vulnerability.
Update the plugin.
- Affected:
- up to 0.9.9
- Fixed in:
- 0.9.9
- Disclosed:
- Dec 21, 2016
Chained Quiz [chained-quiz] < 1.3.2.1
unknown
Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.1).
Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...
- Affected:
- up to 1.3.2.1
- Fixed in:
- 1.3.2.1
Chained Quiz [chained-quiz] < 1.3.2.1
unknown
Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.1).
Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...
- Affected:
- up to 1.3.2.1
- Fixed in:
- 1.3.2.1
Chained Quiz [chained-quiz] < 1.3.2.1
unknown
Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.1).
Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...
- Affected:
- up to 1.3.2.1
- Fixed in:
- 1.3.2.1
Chained Quiz [chained-quiz] < 1.3.2.1
unknown
Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.1).
Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...
- Affected:
- up to 1.3.2.1
- Fixed in:
- 1.3.2.1
Chained Quiz [chained-quiz] < 1.3.2.4
unknown
Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.4).
Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...
- Affected:
- up to 1.3.2.4
- Fixed in:
- 1.3.2.4
Chained Quiz [chained-quiz] < 1.3.2.5
unknown
Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.5).
Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to force higher privileged users to execute unwante...
- Affected:
- up to 1.3.2.5
- Fixed in:
- 1.3.2.5
Chained Quiz [chained-quiz] < 1.3.2.3
unknown
Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.3).
Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...
- Affected:
- up to 1.3.2.3
- Fixed in:
- 1.3.2.3
Chained Quiz [chained-quiz] < 1.3.2.5
unknown
Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.5).
Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to force higher privileged users to execute unwante...
- Affected:
- up to 1.3.2.5
- Fixed in:
- 1.3.2.5
Chained Quiz [chained-quiz] < 1.3.2.3
unknown
Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.3).
Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...
- Affected:
- up to 1.3.2.3
- Fixed in:
- 1.3.2.3
Chained Quiz [chained-quiz] < 1.3.2.3
unknown
Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.3).
Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...
- Affected:
- up to 1.3.2.3
- Fixed in:
- 1.3.2.3
Chained Quiz [chained-quiz] < 1.3.2.4
unknown
Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.4).
Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...
- Affected:
- up to 1.3.2.4
- Fixed in:
- 1.3.2.4
Chained Quiz [chained-quiz] < 1.3.2.5
unknown
Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.5).
Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to force higher privileged users to execute unwante...
- Affected:
- up to 1.3.2.5
- Fixed in:
- 1.3.2.5
Chained Quiz [chained-quiz] < 1.3.2.1
unknown
Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.1).
Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...
- Affected:
- up to 1.3.2.1
- Fixed in:
- 1.3.2.1
Chained Quiz [chained-quiz] < 1.1.9.1
unknown
WordPress Plugin Plugin Chained Quiz latest (1.1.9) and before suffers from a Stored XSS vulnerability in the sender_name, admin_subject and user_subject POST parameter when an admin completes the setting for plugin (as a result, the severity is very low)
- Affected:
- up to 1.1.9.1
- Fixed in:
- 1.1.9.1
Chained Quiz [chained-quiz] < 0.9.9
unknown
The Chained Quiz WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 0.9.9
- Fixed in:
- 0.9.9