Quiz Tool Lite <= 2.3.15 - Authenticated (Admin+) Stored Cross-Site Scripting
mediumThe Quiz Tool Lite WordPress plugin through 2.3.15 does not sanitize multiple input fields used when creating or managing quizzes and in other setting options, allowing high privilege users to inject arbitrary web scripts in pages even when the unfiltered_html capability is disallowed that will execute whenever a user...
- CVSS:
- 4.8
- Affected:
- up to 2.3.15
- Fix:
- No patched version reported
- Disclosed:
- Oct 11, 2021