CVE-2024-1078: Quiz Maker <= 6.5.2.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Creation & Modification
The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the aysquickstart() and addquestionrows() functions in all versions up to, and including, 6.5.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary quizzes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1078?
CVE-2024-1078 is considered a high-severity vulnerability due to its potential for unauthorized data modification.
How do I fix CVE-2024-1078?
To fix CVE-2024-1078, update the Quiz Maker plugin to version 6.5.2.5 or later.
Who is affected by CVE-2024-1078?
CVE-2024-1078 affects all versions of the Quiz Maker plugin for WordPress up to and including 6.5.2.4.
What types of attacks does CVE-2024-1078 allow?
CVE-2024-1078 allows authenticated attackers, at the subscriber level, to modify quiz data unauthorizedly.
What functions are vulnerable in CVE-2024-1078?
CVE-2024-1078 involves a missing capability check on the ays_quick_start() and add_question_rows() functions.