CVE-2024-8617: Quiz Maker <= 6.5.9.8 - Admin+ Stored XSS
The Quiz Maker WordPress plugin before 6.5.9.9 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8617?
CVE-2024-8617 has a high severity due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-8617?
To fix CVE-2024-8617, update the Quiz Maker WordPress plugin to version 6.5.9.9 or later.
Who is affected by CVE-2024-8617?
High-privilege users, including admins, using Quiz Maker versions before 6.5.9.9 are affected by CVE-2024-8617.
What types of attacks can CVE-2024-8617 enable?
CVE-2024-8617 can enable Stored Cross-Site Scripting attacks on vulnerable WordPress sites.
Is multisite affected by CVE-2024-8617?
Yes, CVE-2024-8617 can affect multisite setups despite the unfiltered_html capability being disallowed.