Stored Cross-Site Scripting in Quiz Organizer Plugin for WordPress
CVE-2024-6810
4.4MEDIUM
Key Information:
- Vendor
- Quizorganizer
- Status
- Quiz Organizer
- Vendor
- CVE Published:
- 26 February 2025
Summary
The Quiz Organizer plugin for WordPress is susceptible to a Stored Cross-Site Scripting flaw due to a lack of adequate input validation and output encoding in all versions up to 2.9.1. This vulnerability enables authenticated attackers with administrator privileges to inject malicious scripts into various pages. These scripts can execute automatically when a user accesses the manipulated page, posing significant risks to users, particularly in multi-site installations and where unfiltered_html is disabled.
Affected Version(s)
Quiz Organizer * <= 2.9.1
References
CVSS V3.1
Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Artem Polynko