plugin

Chained Quiz Vulnerabilities

65 known security issues reported for the Chained Quiz WordPress plugin. Most recent disclosed Sep 17, 2025.

1 critical 23 medium

Running Chained Quiz on your site? Check whether your installed version is affected.

Scan your site free

Chained Quiz <= 1.3.5 - Unauthenticated Insecure Direct Object Reference via Cookie

medium

The Chained Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference in version 1.3.4 and below via the quiz submission and completion mechanisms due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to hijack and modify other users' quiz attempts by...

CVSS:
5.3
Affected:
up to 1.3.5
Fixed in:
1.3.6
Disclosed:
Sep 17, 2025

CVE-2025-10493 on NVD →

Chained Quiz <= 1.3.2.9 - Authenticated (Admin+) Server-Side Request Forgery

medium

The Chained Quiz plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.2.9. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application which can be u...

CVSS:
5.5
Affected:
up to 1.3.2.9
Fixed in:
1.3.3
Disclosed:
Jan 24, 2025

CVE-2025-24701 on NVD →

Chained Quiz [chained-quiz] < 1.3.3

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in Kiboko Labs Chained Quiz allows Server Side Request Forgery. This issue affects Chained Quiz: from n/a through 1.3.2.9.

Affected:
up to 1.3.3
Fixed in:
1.3.3
Disclosed:
Jan 24, 2025

CVE-2025-24701 on NVD →

Chained Quiz [chained-quiz] < 1.3.2.9

unknown

[en] Missing Authorization vulnerability in Kiboko Labs Chained Quiz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chained Quiz: from n/a through 1.3.2.8.

Affected:
up to 1.3.2.9
Fixed in:
1.3.2.9
Disclosed:
Nov 1, 2024

CVE-2024-37921 on NVD →

Chained Quiz [chained-quiz] < 1.3.2.9

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kiboko Labs Chained Quiz allows Stored XSS.This issue affects Chained Quiz: from n/a through 1.3.2.8.

Affected:
up to 1.3.2.9
Fixed in:
1.3.2.9
Disclosed:
Jul 21, 2024

CVE-2024-37446 on NVD →

Chained Quiz <= 1.3.2.8 - Missing Authorization

medium

The Chained Quiz plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the finalize() function in all versions up to, and including, 1.3.2.8. This makes it possible for unauthenticated attackers to answer quizzes that require logging in.

CVSS:
5.3
Affected:
up to 1.3.2.8
Fixed in:
1.3.2.9
Disclosed:
Jul 9, 2024

CVE-2024-37921 on NVD →

Chained Quiz <= 1.3.2.8 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages...

CVSS:
4.4
Affected:
up to 1.3.2.8
Fixed in:
1.3.2.9
Disclosed:
Jun 28, 2024

CVE-2024-37446 on NVD →

Chained Quiz [chained-quiz] < 1.3.2.6

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Chained Quiz plugin <= 1.3.2.5 versions.

Affected:
up to 1.3.2.6
Fixed in:
1.3.2.6
Disclosed:
Apr 7, 2023

CVE-2023-25027 on NVD →

Chained Quiz <= 1.3.2.5 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions, to inject arbitrary web scripts in pages that...

CVSS:
5.5
Affected:
up to 1.3.2.5
Fixed in:
1.3.2.6
Disclosed:
Feb 6, 2023

CVE-2023-25027 on NVD →

Chained Quiz <= 1.3.2 - Reflected Cross-Site Scripting via datef

medium

The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'datef' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...

CVSS:
6.1
Affected:
up to 1.3.2
Fixed in:
1.3.2.1
Disclosed:
Dec 2, 2022

CVE-2022-4208 on NVD →

Chained Quiz <= 1.3.2 - Reflected Cross-Site Scripting via emailf

medium

The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'emailf' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...

CVSS:
6.1
Affected:
up to 1.3.2
Fixed in:
1.3.2.1
Disclosed:
Dec 2, 2022

CVE-2022-4211 on NVD →

Chained Quiz <= 1.3.2.3 - Reflected Cross-Site Scripting via ip

medium

The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ip' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...

CVSS:
6.1
Affected:
up to 1.3.2.3
Fixed in:
1.3.2.4
Disclosed:
Dec 2, 2022

CVE-2022-4214 on NVD →

Chained Quiz <= 1.3.2.2 - Reflected Cross-Site Scripting via dn

medium

The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dn' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...

CVSS:
6.1
Affected:
up to 1.3.2.2
Fixed in:
1.3.2.3
Disclosed:
Dec 2, 2022

CVE-2022-4213 on NVD →

Chained Quiz <= 1.3.2 - Reflected Cross-Site Scripting via dnf

medium

The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dnf' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc...

CVSS:
6.1
Affected:
up to 1.3.2
Fixed in:
1.3.2.1
Disclosed:
Dec 2, 2022

CVE-2022-4210 on NVD →

Chained Quiz <= 1.3.2 - Reflected Cross-Site Scripting via ipf

medium

The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ipf' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc...

CVSS:
6.1
Affected:
up to 1.3.2
Fixed in:
1.3.2.1
Disclosed:
Dec 2, 2022

CVE-2022-4212 on NVD →

Chained Quiz <= 1.3.2.3 - Reflected Cross-Site Scripting via date

medium

The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...

CVSS:
6.1
Affected:
up to 1.3.2.3
Fixed in:
1.3.2.4
Disclosed:
Dec 2, 2022

CVE-2022-4215 on NVD →

Chained Quiz <= 1.3.2 - Reflected Cross-Site Scripting via pointsf

medium

The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pointsf' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary we...

CVSS:
6.1
Affected:
up to 1.3.2
Fixed in:
1.3.2.1
Disclosed:
Dec 2, 2022

CVE-2022-4209 on NVD →

Chained Quiz <= 1.3.2.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Facebook App ID

medium

The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'facebook_appid' parameter in versions up to, and including, 1.3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrar...

CVSS:
5.5
Affected:
up to 1.3.2.2
Fixed in:
1.3.2.3
Disclosed:
Dec 2, 2022

CVE-2022-4216 on NVD →

Chained Quiz <= 1.3.2.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Mailchimp API Key

medium

The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key' parameter in versions up to, and including, 1.3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrary web s...

CVSS:
5.5
Affected:
up to 1.3.2.2
Fixed in:
1.3.2.3
Disclosed:
Dec 2, 2022

CVE-2022-4217 on NVD →

Chained Quiz <= 1.3.2.4 - Cross-Site Request Forgery to Question Deletion

medium

The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4. This is due to missing nonce validation on the list_questions() function. This makes it possible for unauthenticated attackers to delete questions from quizzes via a forged request granted they c...

CVSS:
5.4
Affected:
up to 1.3.2.4
Fixed in:
1.3.2.5
Disclosed:
Dec 2, 2022

CVE-2022-4220 on NVD →

Chained Quiz <= 1.3.2.4 - Cross-Site Request Forgery to Submitted Response Deletion

medium

The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4. This is due to missing nonce validation on the manage() function. This makes it possible for unauthenticated attackers to delete submitted quiz responses via a forged request granted they can tri...

CVSS:
5.4
Affected:
up to 1.3.2.4
Fixed in:
1.3.2.5
Disclosed:
Dec 2, 2022

CVE-2022-4219 on NVD →

Chained Quiz <= 1.3.2.4 - Cross-Site Request Forgery to Arbitrary Quiz Deletion and Copying

medium

The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4. This is due to missing nonce validation on the list_quizzes() function. This makes it possible for unauthenticated attackers to delete quizzes and copy quizzes via a forged request granted they c...

CVSS:
5.4
Affected:
up to 1.3.2.4
Fixed in:
1.3.2.5
Disclosed:
Dec 2, 2022

CVE-2022-4218 on NVD →

Chained Quiz [chained-quiz] < 1.3.2.5

unknown

[en] The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4. This is due to missing nonce validation on the manage() function. This makes it possible for unauthenticated attackers to delete submitted quiz responses via a forged request granted they ca...

Affected:
up to 1.3.2.5
Fixed in:
1.3.2.5
Disclosed:
Dec 2, 2022

CVE-2022-4219 on NVD →

Chained Quiz [chained-quiz] < 1.3.2.1

unknown

[en] The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'datef' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...

Affected:
up to 1.3.2.1
Fixed in:
1.3.2.1
Disclosed:
Dec 2, 2022

CVE-2022-4208 on NVD →

Chained Quiz [chained-quiz] < 1.3.2.1

unknown

[en] The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pointsf' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra...

Affected:
up to 1.3.2.1
Fixed in:
1.3.2.1
Disclosed:
Dec 2, 2022

CVE-2022-4209 on NVD →

Chained Quiz [chained-quiz] < 1.3.2.1

unknown

[en] The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dnf' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w...

Affected:
up to 1.3.2.1
Fixed in:
1.3.2.1
Disclosed:
Dec 2, 2022

CVE-2022-4210 on NVD →

Chained Quiz [chained-quiz] < 1.3.2.1

unknown

[en] The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'emailf' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...

Affected:
up to 1.3.2.1
Fixed in:
1.3.2.1
Disclosed:
Dec 2, 2022

CVE-2022-4211 on NVD →

Chained Quiz [chained-quiz] < 1.3.2.3

unknown

[en] The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ipf' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w...

Affected:
up to 1.3.2.3
Fixed in:
1.3.2.3
Disclosed:
Dec 2, 2022

CVE-2022-4212 on NVD →

Chained Quiz [chained-quiz] < 1.3.2.3

unknown

[en] The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dn' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...

Affected:
up to 1.3.2.3
Fixed in:
1.3.2.3
Disclosed:
Dec 2, 2022

CVE-2022-4213 on NVD →

Chained Quiz [chained-quiz] < 1.3.2.4

unknown

[en] The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ip' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...

Affected:
up to 1.3.2.4
Fixed in:
1.3.2.4
Disclosed:
Dec 2, 2022

CVE-2022-4214 on NVD →

Chained Quiz [chained-quiz] < 1.3.2.4

unknown

[en] The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...

Affected:
up to 1.3.2.4
Fixed in:
1.3.2.4
Disclosed:
Dec 2, 2022

CVE-2022-4215 on NVD →

Chained Quiz [chained-quiz] < 1.3.2.3

unknown

[en] The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'facebook_appid' parameter in versions up to, and including, 1.3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arb...

Affected:
up to 1.3.2.3
Fixed in:
1.3.2.3
Disclosed:
Dec 2, 2022

CVE-2022-4216 on NVD →

Chained Quiz [chained-quiz] < 1.3.2.3

unknown

[en] The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key' parameter in versions up to, and including, 1.3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrary...

Affected:
up to 1.3.2.3
Fixed in:
1.3.2.3
Disclosed:
Dec 2, 2022

CVE-2022-4217 on NVD →

Chained Quiz [chained-quiz] < 1.3.2.5

unknown

[en] The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4. This is due to missing nonce validation on the list_quizzes() function. This makes it possible for unauthenticated attackers to delete quizzes and copy quizzes via a forged request granted t...

Affected:
up to 1.3.2.5
Fixed in:
1.3.2.5
Disclosed:
Dec 2, 2022

CVE-2022-4218 on NVD →

Chained Quiz [chained-quiz] < 1.3.2.5

unknown

[en] The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4. This is due to missing nonce validation on the list_questions() function. This makes it possible for unauthenticated attackers to delete questions from quizzes via a forged request granted t...

Affected:
up to 1.3.2.5
Fixed in:
1.3.2.5
Disclosed:
Dec 2, 2022

CVE-2022-4220 on NVD →

Chained Quiz [chained-quiz] < 1.2.7.2

unknown

[en] The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings.

Affected:
up to 1.2.7.2
Fixed in:
1.2.7.2
Disclosed:
Oct 11, 2021

CVE-2021-24690 on NVD →

Chained Quiz < 1.2.7.2 - Cross-Site Scripting

medium

The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings.

CVSS:
5.4
Affected:
up to 1.2.7.2
Fixed in:
1.2.7.2
Disclosed:
Sep 7, 2021

CVE-2021-24690 on NVD →

Chained Quiz [chained-quiz] < 1.0.9

unknown

[en] controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote unauthenticated users to execute arbitrary SQL commands via the 'answer' and 'answers' parameters.

Affected:
up to 1.0.9
Fixed in:
1.0.9
Disclosed:
Mar 10, 2020

CVE-2018-14502 on NVD →

Chained Quiz <= 1.1.9 -Stored Cross-Site Scripting

medium

The Chained Quiz for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘chained_admin_subject', 'chained_user_subject', 'chained_sender_name', 'chained_sender_email' and 'go_ahead_value' values in versions up to, and including, 1.1.9.0 due to insufficient input sanitization and output escaping. This makes...

CVSS:
6.4
Affected:
up to 1.1.9
Fixed in:
1.1.9.1
Disclosed:
Feb 21, 2020

Chained Quiz [chained-quiz] < 1.1.9.1

unknown

The Chained Quiz for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘chained_admin_subject', 'chained_user_subject', 'chained_sender_name', 'chained_sender_email' and 'go_ahead_value' values in versions up to, and including, 1.1.9.0 due to insufficient input sanitization and output escaping. This makes...

Affected:
up to 1.1.9.1
Fixed in:
1.1.9.1
Disclosed:
Feb 21, 2020

Chained Quiz [chained-quiz] < 1.1.9.1

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by khoabda in WordPress Chained Quiz plugin (versions <= 1.1.9).

Affected:
up to 1.1.9.1
Fixed in:
1.1.9.1
Disclosed:
Feb 21, 2020

Chained Quiz [chained-quiz] < 1.1.8.2

unknown

[en] The chained-quiz plugin 1.1.8.1 for WordPress has reflected XSS via the wp-admin/admin-ajax.php total_questions parameter.

Affected:
up to 1.1.8.2
Fixed in:
1.1.8.2
Disclosed:
Jan 17, 2020

CVE-2020-7104 on NVD →

Chained Quiz <= 1.1.8.1 - Reflected Cross-Site Scripting

medium

The chained-quiz plugin 1.1.8.1 for WordPress has reflected XSS via the wp-admin/admin-ajax.php total_questions parameter.

CVSS:
6.1
Affected:
up to 1.1.8.2
Fixed in:
1.1.8.2
Disclosed:
Jan 16, 2020

CVE-2020-7104 on NVD →

Chained Quiz [chained-quiz] < 1.0

unknown

[en] The chained-quiz plugin before 1.0 for WordPress has multiple XSS issues.

Affected:
up to 1.0
Fixed in:
1.0
Disclosed:
Aug 20, 2019

CVE-2016-10892 on NVD →

Chained Quiz <= 1.0.8.2 - Unauthenticated SQL Injection

critical

controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote unauthenticated users to execute arbitrary SQL commands via the 'answer' and 'answers' parameters.

CVSS:
9.8
Affected:
up to 1.0.9
Fixed in:
1.0.9
Disclosed:
Aug 16, 2018

CVE-2018-14502 on NVD →

Chained Quiz Plugin < 1.0 - Cross-Site Scripting

medium

The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 0.9.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if t...

CVSS:
6.1
Affected:
up to 1.0
Fixed in:
1.0
Disclosed:
Jan 12, 2017

CVE-2016-10892 on NVD →

Chained Quiz [chained-quiz] < 1.0

unknown

WordPress Chained Quiz plugin is prone to a cross site scripting vulnerability. Some PHP variables such as $vars[‘question’]” and “$vars[‘qtype’]” are not sanitized. Update the plugin.

Affected:
up to 1.0
Fixed in:
1.0
Disclosed:
Jan 12, 2017

Chained Quiz <= 0.9.8 - Cross-Site Scripting

medium

The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.9.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.4
Affected:
up to 0.9.8
Fixed in:
0.9.9
Disclosed:
Dec 21, 2016

Chained Quiz [chained-quiz] < 0.9.9

unknown

The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.9.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 0.9.9
Fixed in:
0.9.9
Disclosed:
Dec 21, 2016

Chained Quiz [chained-quiz] < 0.9.9

unknown

This plugin is prone to a cross site scripting vulnerability. Update the plugin.

Affected:
up to 0.9.9
Fixed in:
0.9.9
Disclosed:
Dec 21, 2016

Chained Quiz [chained-quiz] < 1.3.2.1

unknown

Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.1). Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...

Affected:
up to 1.3.2.1
Fixed in:
1.3.2.1

Chained Quiz [chained-quiz] < 1.3.2.1

unknown

Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.1). Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...

Affected:
up to 1.3.2.1
Fixed in:
1.3.2.1

Chained Quiz [chained-quiz] < 1.3.2.1

unknown

Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.1). Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...

Affected:
up to 1.3.2.1
Fixed in:
1.3.2.1

Chained Quiz [chained-quiz] < 1.3.2.1

unknown

Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.1). Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...

Affected:
up to 1.3.2.1
Fixed in:
1.3.2.1

Chained Quiz [chained-quiz] < 1.3.2.4

unknown

Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.4). Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...

Affected:
up to 1.3.2.4
Fixed in:
1.3.2.4

Chained Quiz [chained-quiz] < 1.3.2.5

unknown

Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.5). Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to force higher privileged users to execute unwante...

Affected:
up to 1.3.2.5
Fixed in:
1.3.2.5

Chained Quiz [chained-quiz] < 1.3.2.3

unknown

Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.3). Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...

Affected:
up to 1.3.2.3
Fixed in:
1.3.2.3

Chained Quiz [chained-quiz] < 1.3.2.5

unknown

Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.5). Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to force higher privileged users to execute unwante...

Affected:
up to 1.3.2.5
Fixed in:
1.3.2.5

Chained Quiz [chained-quiz] < 1.3.2.3

unknown

Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.3). Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...

Affected:
up to 1.3.2.3
Fixed in:
1.3.2.3

Chained Quiz [chained-quiz] < 1.3.2.3

unknown

Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.3). Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...

Affected:
up to 1.3.2.3
Fixed in:
1.3.2.3

Chained Quiz [chained-quiz] < 1.3.2.4

unknown

Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.4). Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...

Affected:
up to 1.3.2.4
Fixed in:
1.3.2.4

Chained Quiz [chained-quiz] < 1.3.2.5

unknown

Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.5). Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to force higher privileged users to execute unwante...

Affected:
up to 1.3.2.5
Fixed in:
1.3.2.5

Chained Quiz [chained-quiz] < 1.3.2.1

unknown

Update the WordPress Chained Quiz plugin to the latest available version (at least 1.3.2.1). Muhammad Zeeshan (Xib3rR4dAr) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Chained Quiz Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...

Affected:
up to 1.3.2.1
Fixed in:
1.3.2.1

Chained Quiz [chained-quiz] < 1.1.9.1

unknown

WordPress Plugin Plugin Chained Quiz latest (1.1.9) and before suffers from a Stored XSS vulnerability in the sender_name, admin_subject and user_subject POST parameter when an admin completes the setting for plugin (as a result, the severity is very low)

Affected:
up to 1.1.9.1
Fixed in:
1.1.9.1

Chained Quiz [chained-quiz] < 0.9.9

unknown

The Chained Quiz WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 0.9.9
Fixed in:
0.9.9

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database