Quiz Maker by AYS <= 6.7.1.29 - Unauthenticated Stored Cross-Site Scripting via 'rate_reason'
medium
The Quiz Maker by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rate_reason' parameter in all versions up to, and including, 6.7.1.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 5.8
- Affected:
- up to 6.7.1.29
- Fixed in:
- 6.7.1.30
- Disclosed:
- May 1, 2026
CVE-2026-6817 on NVD →
Quiz Maker <= 6.7.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `vc_quizmaker` shortcode in all versions up to, and including, 6.7.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contri...
- CVSS:
- 6.4
- Affected:
- up to 6.7.1.7
- Fixed in:
- 6.7.1.8
- Disclosed:
- Feb 19, 2026
CVE-2026-2384 on NVD →
Quiz Maker <= 6.7.1.2 - Cross-Site Request Forgery
medium
The Quiz Maker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.7.1.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can tric...
- CVSS:
- 4.3
- Affected:
- up to 6.7.1.2
- Fixed in:
- 6.7.1.3
- Disclosed:
- Feb 10, 2026
CVE-2026-32342 on NVD →
Quiz Maker [quiz-maker] < 6.7.0.89
unknown
[en] The Quiz Maker WordPress plugin before 6.7.0.89 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 6.7.0.89
- Fixed in:
- 6.7.0.89
- Disclosed:
- Jan 12, 2026
CVE-2025-14579 on NVD →
Quiz Maker <= 6.7.0.88 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.7.0.88 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages...
- CVSS:
- 4.4
- Affected:
- up to 6.7.0.88
- Fixed in:
- 6.7.0.89
- Disclosed:
- Dec 22, 2025
CVE-2025-14579 on NVD →
Quiz Maker [quiz-maker] <= 6.7.0.82 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Quiz Maker quiz-maker allows Cross Site Request Forgery.This issue affects Quiz Maker: from n/a through <= 6.7.0.82.
- Affected:
- up to 6.7.0.82
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-67595 on NVD →
Quiz Maker <= 6.7.0.82 - Cross-Site Request Forgery
medium
The Quiz Maker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.7.0.82. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site adminis...
- CVSS:
- 4.3
- Affected:
- up to 6.7.0.82
- Fixed in:
- 6.7.0.83
- Disclosed:
- Dec 2, 2025
CVE-2025-67595 on NVD →
Quiz Maker [quiz-maker] < 6.7.0.81
unknown
[en] The Quiz Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.7.0.80. This is due to the plugin exposing quiz answers through the ays_quiz_check_answer AJAX action without proper authorization checks. The endpoint only validates a nonce, but that same n...
- Affected:
- up to 6.7.0.81
- Fixed in:
- 6.7.0.81
- Disclosed:
- Nov 19, 2025
CVE-2025-12426 on NVD →
Quiz Maker <= 6.7.0.80 - Unauthenticated Sensitive Information Exposure
medium
The Quiz Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.7.0.80. This is due to the plugin exposing quiz answers through the ays_quiz_check_answer AJAX action without proper authorization checks. The endpoint only validates a nonce, but that same nonce...
- CVSS:
- 5.3
- Affected:
- up to 6.7.0.80
- Fixed in:
- 6.7.0.81
- Disclosed:
- Nov 18, 2025
CVE-2025-12426 on NVD →
Quiz Maker <= 6.7.0.65 - Unauthenticated Sensitive Information Exposure
medium
The Quiz Maker Business plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.7.0.65. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 6.7.0.65
- Fixed in:
- 6.7.0.66
- Disclosed:
- Sep 22, 2025
CVE-2025-58015 on NVD →
Quiz Maker <= 6.7.0.64 - Cross-Site Request Forgery
medium
The Quiz Maker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.7.0.64. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can tri...
- CVSS:
- 4.3
- Affected:
- up to 6.7.0.64
- Fixed in:
- 6.7.0.65
- Disclosed:
- Sep 22, 2025
CVE-2025-58014 on NVD →
Quiz Maker [quiz-maker] < 6.7.0.57
unknown
[en] The Quiz Maker plugin for WordPress is vulnerable to SQL Injection via spoofed IP headers in all versions up to, and including, 6.7.0.56 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to...
- Affected:
- up to 6.7.0.57
- Fixed in:
- 6.7.0.57
- Disclosed:
- Sep 17, 2025
CVE-2025-10042 on NVD →
Quiz Maker <= 6.7.0.56 - Unauthenticated SQL Injection
medium
The Quiz Maker plugin for WordPress is vulnerable to SQL Injection via spoofed IP headers in all versions up to, and including, 6.7.0.56 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to appe...
- CVSS:
- 5.9
- Affected:
- up to 6.7.0.56
- Fixed in:
- 6.7.0.57
- Disclosed:
- Sep 16, 2025
CVE-2025-10042 on NVD →
Quiz Maker [quiz-maker] < 6.6.8.8
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker allows SQL Injection. This issue affects Quiz Maker: from n/a through 6.6.8.7.
- Affected:
- up to 6.6.8.8
- Fixed in:
- 6.6.8.8
- Disclosed:
- Apr 1, 2025
CVE-2025-30774 on NVD →
Quiz Maker <= 6.6.8.7 - Unauthenticated SQL Injection
high
The Quiz Maker plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.6.8.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries in...
- CVSS:
- 7.5
- Affected:
- up to 6.6.8.7
- Fixed in:
- 6.6.8.8
- Disclosed:
- Mar 29, 2025
CVE-2025-30774 on NVD →
Quiz Maker [quiz-maker] >= 7.0.0 - < 8.8.0.100
unknown
[en] The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ays_save_google_credentials' function in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and in...
- Affected:
- 7.0.0 – 8.8.0.100
- Fixed in:
- 8.8.0.100
- Disclosed:
- Jan 26, 2025
CVE-2024-10574 on NVD →
Quiz Maker [quiz-maker] >= 7.0.0 - < 8.8.0.100
unknown
[en] The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency) due to insufficient input sani...
- Affected:
- 7.0.0 – 8.8.0.100
- Fixed in:
- 8.8.0.100
- Disclosed:
- Jan 26, 2025
CVE-2024-10636 on NVD →
Quiz Maker [quiz-maker] >= 7.0.0 - < 8.8.0.100
unknown
[en] The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency). This is due to the software allowing users to execute an a...
- Affected:
- 7.0.0 – 8.8.0.100
- Fixed in:
- 8.8.0.100
- Disclosed:
- Jan 26, 2025
CVE-2024-10633 on NVD →
Quiz Maker [quiz-maker] >= 7.0.0 - < 8.8.0.100
unknown
[en] The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency) due to insufficient escaping on the user supplied pa...
- Affected:
- 7.0.0 – 8.8.0.100
- Fixed in:
- 8.8.0.100
- Disclosed:
- Jan 26, 2025
CVE-2024-10628 on NVD →
Quiz Maker Business, Developer, and Agency <= (Multiple Versions) - Unauthenticated SQL Injection via id
high
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency) due to insufficient escaping on the user supplied paramet...
- CVSS:
- 7.5
- Affected:
- 30.0.0 – 31.8.0
- Fixed in:
- 31.8.0.100
- Disclosed:
- Jan 25, 2025
CVE-2024-10628 on NVD →
Quiz Maker Business, Developer, and Agency <= (Multiple Versions) - Unauthenticated Arbitrary Shortcode Execution via content
high
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency). This is due to the software allowing users to execute an action...
- CVSS:
- 7.3
- Affected:
- 30.0.0 – 31.8.0
- Fixed in:
- 31.8.0.100
- Disclosed:
- Jan 25, 2025
CVE-2024-10633 on NVD →
Quiz Maker Business, Developer, and Agency <= (Multiple Versions) - Missing Authorization to Google Sheets Integration Credentials Modification and Stored Cross-Site Scripting
high
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ays_save_google_credentials' function in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and includi...
- CVSS:
- 7.2
- Affected:
- 30.0.0 – 31.8.0
- Fixed in:
- 31.8.0.100
- Disclosed:
- Jan 25, 2025
CVE-2024-10574 on NVD →
Quiz Maker Business, Developer, and Agency <= (Multiple Versions) - Reflected DOM-Based Cross-Site Scripting via content
medium
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency) due to insufficient input sanitizat...
- CVSS:
- 6.1
- Affected:
- 30.0.0 – 31.8.0
- Fixed in:
- 31.8.0.100
- Disclosed:
- Jan 25, 2025
CVE-2024-10636 on NVD →
Quiz Maker [quiz-maker] < 6.5.1.2
unknown
[en] Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez Login Register: from n/a through 3.2.5.
- Affected:
- up to 6.5.1.2
- Fixed in:
- 6.5.1.2
- Disclosed:
- Sep 17, 2024
CVE-2024-21743 on NVD →
Quiz Maker <= 6.5.9.8 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbi...
- CVSS:
- 4.4
- Affected:
- up to 6.5.9.8
- Fixed in:
- 6.5.9.9
- Disclosed:
- Sep 16, 2024
CVE-2024-8617 on NVD →
Quiz Maker [quiz-maker] < 6.5.8.4
unknown
[en] The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthe...
- Affected:
- up to 6.5.8.4
- Fixed in:
- 6.5.8.4
- Disclosed:
- Jun 25, 2024
CVE-2024-6028 on NVD →
Quiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter
critical
The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthentica...
- CVSS:
- 9.8
- Affected:
- up to 6.5.8.3
- Fixed in:
- 6.5.8.4
- Disclosed:
- Jun 24, 2024
CVE-2024-6028 on NVD →
Quiz Maker [quiz-maker] < 6.3.9.5
unknown
[en] Missing Authorization vulnerability in Quiz Maker team Quiz Maker.This issue affects Quiz Maker: from n/a through 6.3.9.4.
- Affected:
- up to 6.3.9.5
- Fixed in:
- 6.3.9.5
- Disclosed:
- Apr 24, 2024
CVE-2023-23985 on NVD →
Quiz Maker [quiz-maker] < 6.5.2.5
unknown
[en] The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_show_results() function in all versions up to, and including, 6.5.2.4. This makes it possible for unauthenticated attackers to fetch arbitrary quiz results which can contain PII.
- Affected:
- up to 6.5.2.5
- Fixed in:
- 6.5.2.5
- Disclosed:
- Feb 7, 2024
CVE-2024-1079 on NVD →
Quiz Maker [quiz-maker] < 6.5.2.5
unknown
[en] The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ays_quick_start() and add_question_rows() functions in all versions up to, and including, 6.5.2.4. This makes it possible for authenticated attackers, with subscriber-level access and abo...
- Affected:
- up to 6.5.2.5
- Fixed in:
- 6.5.2.5
- Disclosed:
- Feb 7, 2024
CVE-2024-1078 on NVD →
Quiz Maker <= 6.5.2.4 - Missing Authorization to Unauthenticated Quiz Data Retrieval
medium
The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_show_results() function in all versions up to, and including, 6.5.2.4. This makes it possible for unauthenticated attackers to fetch arbitrary quiz results which can contain PII.
- CVSS:
- 5.3
- Affected:
- up to 6.5.2.4
- Fixed in:
- 6.5.2.5
- Disclosed:
- Feb 6, 2024
CVE-2024-1079 on NVD →
Quiz Maker <= 6.5.2.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Creation & Modification
medium
The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ays_quick_start() and add_question_rows() functions in all versions up to, and including, 6.5.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, t...
- CVSS:
- 4.3
- Affected:
- up to 6.5.2.4
- Fixed in:
- 6.5.2.5
- Disclosed:
- Feb 6, 2024
CVE-2024-1078 on NVD →
Quiz Maker <= 6.5.0.5 - Denial of Service
medium
The Quiz Maker plugin for WordPress is vulnerable to denial of service in all versions up to, and including, 6.5.0.5. The cause is unknown This makes it possible for attackers to potentially deny access to resources.
- CVSS:
- 5.3
- Affected:
- up to 6.5.0.5
- Fixed in:
- 6.5.0.6
- Disclosed:
- Jan 12, 2024
CVE-2024-22027 on NVD →
Quiz Maker [quiz-maker] < 6.5.0.6
unknown
[en] Improper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a remote authenticated attacker to perform a Denial of Service (DoS) attack against external services.
- Affected:
- up to 6.5.0.6
- Fixed in:
- 6.5.0.6
- Disclosed:
- Jan 12, 2024
CVE-2024-22027 on NVD →
Quiz Maker <= 6.5.1.1 - Missing Authorization
medium
The Quiz Maker plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.5.1.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.
- CVSS:
- 4.3
- Affected:
- up to 6.5.1.1
- Fixed in:
- 6.5.1.2
- Disclosed:
- Jan 5, 2024
CVE-2024-21743 on NVD →
Quiz Maker [quiz-maker] < 6.4.9.5
unknown
[en] The Quiz Maker WordPress plugin before 6.4.9.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting
- Affected:
- up to 6.4.9.5
- Fixed in:
- 6.4.9.5
- Disclosed:
- Dec 26, 2023
CVE-2023-6166 on NVD →
Quiz Maker [quiz-maker] < 6.4.9.5
unknown
[en] The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticated attacker to perform a search for users of the system, ultimately leaking user email addresses.
- Affected:
- up to 6.4.9.5
- Fixed in:
- 6.4.9.5
- Disclosed:
- Dec 26, 2023
CVE-2023-6155 on NVD →
Quiz Maker <= 6.4.9.4 - Reflected Cross-Site Scripting
medium
The Quiz Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.4.9.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tr...
- CVSS:
- 6.1
- Affected:
- up to 6.4.9.4
- Fixed in:
- 6.4.9.5
- Disclosed:
- Nov 30, 2023
CVE-2023-6166 on NVD →
Quiz Maker <= 6.4.9.4 - Missing Authorization to Email Disclosure
medium
The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_quiz_author_user_search function in all versions up to 6.4.9.5 (exclusive). This makes it possible for unauthenticated attackers to perform a search for users and obtain user email addresses.
- CVSS:
- 5.3
- Affected:
- up to 6.4.9.4
- Fixed in:
- 6.4.9.5
- Disclosed:
- Nov 30, 2023
CVE-2023-6155 on NVD →
Quiz Maker [quiz-maker] < 6.4.2.7
unknown
[en] The Quiz Maker WordPress plugin before 6.4.2.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 6.4.2.7
- Fixed in:
- 6.4.2.7
- Disclosed:
- Jun 5, 2023
CVE-2023-2571 on NVD →
Quiz Maker <= 6.4.2.6 - Reflected Cross-Site Scripting
medium
The Quiz Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.4.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tr...
- CVSS:
- 6.1
- Affected:
- up to 6.4.2.6
- Fixed in:
- 6.4.2.7
- Disclosed:
- May 15, 2023
CVE-2023-2571 on NVD →
Quiz Maker <= 6.3.9.4 - Content Spoofing
medium
The Quiz Maker plugin for WordPress is vulnerable to content spoofing in versions up to, and including 6.3.9.4. This makes it possible for unauthenticated attackers to inject content that may alter the content and display of select pages.
- CVSS:
- 5.3
- Affected:
- up to 6.3.9.4
- Fixed in:
- 6.3.9.5
- Disclosed:
- Jan 20, 2023
CVE-2023-23985 on NVD →
Quiz Maker [quiz-maker] < 6.2.0.9
unknown
[en] The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL statements, leading to SQL injection issues in the admin dashboard
- Affected:
- up to 6.2.0.9
- Fixed in:
- 6.2.0.9
- Disclosed:
- Aug 2, 2021
CVE-2021-24456 on NVD →
Quiz Maker <= 6.2.0.8 - SQL Injection
high
The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL statements, leading to SQL injection issues in the admin dashboard
- CVSS:
- 7.2
- Affected:
- up to 6.2.0.9
- Fixed in:
- 6.2.0.9
- Disclosed:
- Jun 29, 2021
CVE-2021-24456 on NVD →
Quiz Maker [quiz-maker] < 6.5.9.9
unknown
- Affected:
- up to 6.5.9.9
- Fixed in:
- 6.5.9.9
CVE-2024-8617 on NVD →