Stored Cross-Site Scripting in Quiz Organizer Plugin for WordPress
CVE-2024-6810

4.4MEDIUM

Key Information:

Vendor
Quizorganizer
Status
Quiz Organizer
Vendor
CVE Published:
26 February 2025

Summary

The Quiz Organizer plugin for WordPress is susceptible to a Stored Cross-Site Scripting flaw due to a lack of adequate input validation and output encoding in all versions up to 2.9.1. This vulnerability enables authenticated attackers with administrator privileges to inject malicious scripts into various pages. These scripts can execute automatically when a user accesses the manipulated page, posing significant risks to users, particularly in multi-site installations and where unfiltered_html is disabled.

Affected Version(s)

Quiz Organizer * <= 2.9.1

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Artem Polynko
.