Stored Cross-Site Scripting in Quiz Organizer Plugin for WordPress
CVE-2024-6810
4.4MEDIUM
What is CVE-2024-6810?
The Quiz Organizer plugin for WordPress is susceptible to a Stored Cross-Site Scripting flaw due to a lack of adequate input validation and output encoding in all versions up to 2.9.1. This vulnerability enables authenticated attackers with administrator privileges to inject malicious scripts into various pages. These scripts can execute automatically when a user accesses the manipulated page, posing significant risks to users, particularly in multi-site installations and where unfiltered_html is disabled.
Affected Version(s)
Quiz Organizer * <= 2.9.1