CVE-2025-30774: WordPress Quiz Maker plugin <= 6.6.8.7 - SQL Injection vulnerability
Published Apr 1, 2025
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker quiz-maker allows SQL Injection.This issue affects Quiz Maker: from n/a through <= 6.6.8.7.
Affected Software
3 affected components
Ays Pro Quiz Maker<=6.6.8.7
WordPress Quiz Maker<=6.6.8.7
ays-pro Quiz Maker Wordpress<6.6.8.8
Remediation
Information
Update the WordPress Quiz Maker plugin to the latest available version (at least 6.6.8.8).
Event History
Apr 1, 2025
CVE Published
via MITRE·05:31 AM
Data Sourced
via MITRE·05:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-30774?
The severity of CVE-2025-30774 is considered high due to its ability to allow SQL Injection attacks.
2
How do I fix CVE-2025-30774?
To fix CVE-2025-30774, upgrade Ays Pro Quiz Maker to a version above 6.6.8.7.
3
What software is affected by CVE-2025-30774?
CVE-2025-30774 affects Ays Pro Quiz Maker and WordPress Quiz Maker up to version 6.6.8.7.
4
What type of vulnerability is CVE-2025-30774?
CVE-2025-30774 is an SQL Injection vulnerability that arises from improper neutralization of special elements in SQL commands.
5
Can CVE-2025-30774 be exploited remotely?
Yes, CVE-2025-30774 can be exploited remotely, allowing attackers to execute unauthorized SQL queries.