CVE-2023-2571: Quiz Maker < 6.4.2.7 - Reflected XSS
The Quiz Maker WordPress plugin before 6.4.2.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-2571?
CVE-2023-2571 is a vulnerability in the Quiz Maker WordPress plugin that allows for Reflected Cross-Site Scripting.
What is the severity of CVE-2023-2571?
The severity of CVE-2023-2571 is medium with a severity value of 6.1.
How does CVE-2023-2571 impact users?
CVE-2023-2571 allows for Reflected Cross-Site Scripting, which could be used against high privilege users such as admins.
How can I fix CVE-2023-2571?
To fix CVE-2023-2571, update the Quiz Maker WordPress plugin to version 6.4.2.7 or later, which includes the necessary escape parameters.
Where can I find more information about CVE-2023-2571?
You can find more information about CVE-2023-2571 on the WPScan website using this reference: https://wpscan.com/vulnerability/2dc02e5c-1c89-4053-a6a7-29ee7b996183