plugin

Examapp Vulnerabilities

6 known security issues reported for the Examapp WordPress plugin. Most recent disclosed Sep 10, 2019.

1 high 1 medium

Running Examapp on your site? Check whether your installed version is affected.

Scan your site free

BPS Online Exam [examapp] <= 1.0

unknown

[en] The examapp plugin 1.0 for WordPress has SQL injection via the wp-admin/admin.php?page=examapp_UserResult id parameter.

Affected:
up to 1.0
Fixed in:
1.0
Disclosed:
Sep 10, 2019

CVE-2017-18602 on NVD →

BPS Online Exam [examapp] <= 1.0 (closed)

unknown

[en] The examapp plugin 1.0 for WordPress has XSS via exam input text fields.

Affected:
up to 1.0
Fixed in:
1.0
Disclosed:
Sep 10, 2019

CVE-2017-18601 on NVD →

BPS Online Exam [examapp] < 1.1

unknown

Authenticated SQL Injection (SQLi) vulnerability found in WordPress IBPS Online Exam plugin <=1.0 versions. Blind SQL Injection possible when logged in as a student. 2017.07.29 - We were unable to find information about patched release of WordPress IBPS Online Exam plugin. Also, we were unable to locate the changelog f...

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Jul 21, 2017

BPS Online Exam [examapp] < 1.1

unknown

Authenticated Stored Cross-site scripting (XSS) vulnerability found in WordPress IBPS Online Exam plugin <=1.0 versions by 8bitsec. The attack is possible when logged in as a student. 2017.07.29 - We were unable to find information about patched release of WordPress IBPS Online Exam plugin. Also, we were unable to loca...

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Jul 21, 2017

IBPS Online Exam <= 1.0 - Cross-Site Scripting

medium

The examapp plugin 1.0 for WordPress has XSS via exam input text fields.

CVSS:
5.4
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Jul 20, 2017

CVE-2017-18601 on NVD →

IBPS Online Exam Plugin for WordPress <= 1.0 - SQL Injection

high

The examapp plugin 1.0 for WordPress has SQL injection via the wp-admin/admin.php?page=examapp_UserResult id parameter.

CVSS:
8.8
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Jul 11, 2017

CVE-2017-18602 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database