Wp-Pro-Quiz [wp-pro-quiz] < 7.11.6
unknown
[en] The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 via the form entries page. This makes it possible for authenticated attackers, with contributor access and above, to view the contents of all form submi...
- Affected:
- up to 7.11.6
- Fixed in:
- 7.11.6
- Disclosed:
- Mar 13, 2024
CVE-2024-1668 on NVD →
Wp-Pro-Quiz [wp-pro-quiz] <= 0.37 (unfixed + closed)
unknown
[en] The WP-Pro-Quiz WordPress plugin through 0.37 does not have CSRF check in place when deleting a quiz, which could allow an attacker to make a logged in admin delete arbitrary quiz on the blog
- Affected:
- up to 0.37
- Fix:
- No patched version reported
- Disclosed:
- Nov 1, 2021
CVE-2020-36504 on NVD →
WP-Pro-Quiz <= 0.37 - Arbitrary Quiz Deletion via Cross-Site Request Forgery
medium
The WP-Pro-Quiz WordPress plugin through 0.37 does not have CSRF check in place when deleting a quiz, which could allow an attacker to make a logged in admin delete arbitrary quiz on the blog
- CVSS:
- 6.5
- Affected:
- up to 0.37
- Fix:
- No patched version reported
- Disclosed:
- Jun 22, 2020
CVE-2020-36504 on NVD →
Wp-Pro-Quiz [wp-pro-quiz] < 7.11.6 (closed)
unknown
- Affected:
- up to 7.11.6
- Fixed in:
- 7.11.6
Wp-Pro-Quiz [wp-pro-quiz] < 7.11.6
unknown
- Affected:
- up to 7.11.6
- Fixed in:
- 7.11.6
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database