CVE-2023-6166: Quiz Maker < 6.4.9.5 - Reflected Cross-Site Scripting
Published Dec 26, 2023
·Updated
The Quiz Maker WordPress plugin before 6.4.9.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting
Affected Software
1 affected component
ays-pro Quiz Maker Wordpress<6.4.9.5
Event History
Dec 26, 2023
CVE Published
06:33 PM
Data Sourced
06:33 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-6166?
CVE-2023-6166 is considered a high severity vulnerability due to the potential for reflected cross-site scripting attacks.
2
How do I fix CVE-2023-6166?
To fix CVE-2023-6166, update the Quiz Maker WordPress plugin to version 6.4.9.5 or later.
3
What impact does CVE-2023-6166 have on my website?
CVE-2023-6166 can allow attackers to execute arbitrary JavaScript in the context of users visiting the affected site.
4
Which versions are affected by CVE-2023-6166?
CVE-2023-6166 affects all versions of the Quiz Maker WordPress plugin prior to 6.4.9.5.
5
Is CVE-2023-6166 just a WordPress issue?
Yes, CVE-2023-6166 specifically affects the Quiz Maker plugin within WordPress environments.