HD Quiz 2.2.0 - 2.2.1 - Cross-Site Request Forgery via Multiple AJAX Handlers
medium
The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to missing or incorrect nonce validation on the hdq_validate_nonce function. This makes it possible for unauthenticated attackers to delete or modify quizzes and questions, create new quizzes, and change...
- CVSS:
- 4.3
- Affected:
- 2.2.0 – 2.2.1
- Fixed in:
- 2.2.2
- Disclosed:
- Jun 26, 2026
CVE-2026-13422 on NVD →
HD Quiz <= 2.0.9 - Missing Authorization
medium
The HD Quiz plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.0.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.0.9
- Fixed in:
- 2.0.10
- Disclosed:
- Jan 24, 2026
CVE-2026-24544 on NVD →
HD Quiz [hd-quiz] <= 2.0.9 (unfixed)
unknown
[en] Missing Authorization vulnerability in Harmonic Design HD Quiz hd-quiz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HD Quiz: from n/a through <= 2.0.9.
- Affected:
- up to 2.0.9
- Fix:
- No patched version reported
- Disclosed:
- Jan 23, 2026
CVE-2026-24544 on NVD →
HD Quiz [hd-quiz] < 2.0.0
unknown
[en] The HD Quiz WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.0
- Disclosed:
- May 15, 2025
CVE-2024-13383 on NVD →
HD Quiz <= 1.8.14 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The HD Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 1.8.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts...
- CVSS:
- 4.4
- Affected:
- up to 1.8.14
- Fixed in:
- 2.0.0
- Disclosed:
- Mar 3, 2025
CVE-2024-13383 on NVD →
HD Quiz [hd-quiz] < 1.8.12
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Harmonic Design HD Quiz allows Stored XSS.This issue affects HD Quiz: from n/a through 1.8.11.
- Affected:
- up to 1.8.12
- Fixed in:
- 1.8.12
- Disclosed:
- Jan 31, 2024
CVE-2024-22161 on NVD →
HD Quiz <= 1.8.11 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings
medium
The HD Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrar...
- CVSS:
- 4.4
- Affected:
- up to 1.8.11
- Fixed in:
- 1.8.12
- Disclosed:
- Jan 16, 2024
CVE-2024-22161 on NVD →
HD Quiz [hd-quiz] < 1.8.4
unknown
[en] The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when generating the Quiz, which could lead to Stored Cross-Site Scripting issues
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.4
- Disclosed:
- Aug 23, 2021
CVE-2021-24571 on NVD →
HD Quiz <= 1.8.3 - Stored Cross-Site Scripting
medium
The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when generating the Quiz, which could lead to Stored Cross-Site Scripting issues
- CVSS:
- 5.4
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.4
- Disclosed:
- Jul 26, 2021
CVE-2021-24571 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database