Quizlord <= 2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Quizlord plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unspecified parameter in versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to inject arbitrary web scripts in pages that will execut...
- CVSS:
- 5.5
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Nov 24, 2022
CVE-2022-4112 on NVD →
Quizlord <= 2.0 - Authenticated Stored Cross-Site Scripting
medium
The Quizlord plugin through 2.0 for WordPress is prone to Stored XSS via the title parameter in a ql_insert action to wp-admin/admin.php.
- CVSS:
- 6.4
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 29, 2018
CVE-2018-17140 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database