plugin

Hd Quiz Vulnerabilities

9 known security issues reported for the Hd Quiz WordPress plugin. Most recent disclosed Jun 26, 2026.

5 medium

Running Hd Quiz on your site? Check whether your installed version is affected.

Scan your site free

HD Quiz 2.2.0 - 2.2.1 - Cross-Site Request Forgery via Multiple AJAX Handlers

medium

The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to missing or incorrect nonce validation on the hdq_validate_nonce function. This makes it possible for unauthenticated attackers to delete or modify quizzes and questions, create new quizzes, and change...

CVSS:
4.3
Affected:
2.2.0 – 2.2.1
Fixed in:
2.2.2
Disclosed:
Jun 26, 2026

CVE-2026-13422 on NVD →

HD Quiz <= 2.0.9 - Missing Authorization

medium

The HD Quiz plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.0.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.0.9
Fixed in:
2.0.10
Disclosed:
Jan 24, 2026

CVE-2026-24544 on NVD →

HD Quiz [hd-quiz] <= 2.0.9 (unfixed)

unknown

[en] Missing Authorization vulnerability in Harmonic Design HD Quiz hd-quiz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HD Quiz: from n/a through <= 2.0.9.

Affected:
up to 2.0.9
Fix:
No patched version reported
Disclosed:
Jan 23, 2026

CVE-2026-24544 on NVD →

HD Quiz [hd-quiz] < 2.0.0

unknown

[en] The HD Quiz WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 2.0.0
Fixed in:
2.0.0
Disclosed:
May 15, 2025

CVE-2024-13383 on NVD →

HD Quiz <= 1.8.14 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The HD Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 1.8.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts...

CVSS:
4.4
Affected:
up to 1.8.14
Fixed in:
2.0.0
Disclosed:
Mar 3, 2025

CVE-2024-13383 on NVD →

HD Quiz [hd-quiz] < 1.8.12

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Harmonic Design HD Quiz allows Stored XSS.This issue affects HD Quiz: from n/a through 1.8.11.

Affected:
up to 1.8.12
Fixed in:
1.8.12
Disclosed:
Jan 31, 2024

CVE-2024-22161 on NVD →

HD Quiz <= 1.8.11 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings

medium

The HD Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrar...

CVSS:
4.4
Affected:
up to 1.8.11
Fixed in:
1.8.12
Disclosed:
Jan 16, 2024

CVE-2024-22161 on NVD →

HD Quiz [hd-quiz] < 1.8.4

unknown

[en] The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when generating the Quiz, which could lead to Stored Cross-Site Scripting issues

Affected:
up to 1.8.4
Fixed in:
1.8.4
Disclosed:
Aug 23, 2021

CVE-2021-24571 on NVD →

HD Quiz <= 1.8.3 - Stored Cross-Site Scripting

medium

The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when generating the Quiz, which could lead to Stored Cross-Site Scripting issues

CVSS:
5.4
Affected:
up to 1.8.4
Fixed in:
1.8.4
Disclosed:
Jul 26, 2021

CVE-2021-24571 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database