CVE-2023-6155: Quiz Maker < 6.4.9.5 - Unauthenticated Email Address Disclosure
Published Dec 26, 2023
·Updated
The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the aysquizauthorusersearch AJAX action, allowing an unauthenticated attacker to perform a search for users of the system, ultimately leaking user email addresses.
Affected Software
1 affected component
ays-pro Quiz Maker Wordpress<6.4.9.5
Event History
Dec 26, 2023
CVE Published
06:33 PM
Data Sourced
06:33 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-6155?
CVE-2023-6155 has a high severity rating due to the potential for unauthenticated user data leakage.
2
How do I fix CVE-2023-6155?
To fix CVE-2023-6155, update the Quiz Maker WordPress plugin to version 6.4.9.5 or later.
3
What does CVE-2023-6155 exploit?
CVE-2023-6155 exploits inadequate authorization in the `ays_quiz_author_user_search` AJAX action.
4
What information can be leaked by CVE-2023-6155?
CVE-2023-6155 allows attackers to leak user email addresses from the system.
5
Who is affected by CVE-2023-6155?
CVE-2023-6155 affects users of the Quiz Maker WordPress plugin prior to version 6.4.9.5.