CVE-2025-14579: Quiz Maker < 6.7.0.89 - Admin+ Stored XSS
The Quiz Maker WordPress plugin before 6.7.0.89 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14579?
CVE-2025-14579 is classified as a high severity vulnerability due to its potential for allowing Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-14579?
To fix CVE-2025-14579, update the Quiz Maker WordPress plugin to version 6.7.0.89 or later.
Who is affected by CVE-2025-14579?
CVE-2025-14579 affects users of the Quiz Maker WordPress plugin prior to version 6.7.0.89, specifically those with high privilege roles such as admin.
What kind of attack can be executed due to CVE-2025-14579?
CVE-2025-14579 could enable attackers to perform Stored Cross-Site Scripting attacks on vulnerable installations.
Is CVE-2025-14579 exploitable in multisite setups?
Yes, CVE-2025-14579 can be exploited in multisite setups even when the unfiltered_html capability is disallowed.