CVE-2025-58014: WordPress Quiz Maker Plugin <= 6.7.0.64 - Cross Site Request Forgery (CSRF) Vulnerability
Published Sep 22, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Quiz Maker quiz-maker allows Cross Site Request Forgery.This issue affects Quiz Maker: from n/a through <= 6.7.0.64.
Affected Software
4 affected components
Ays Pro Quiz Maker>=6.7.0.61
Ays Quiz Maker<=6.7.0.61
WordPress Quiz Maker Plugin<=6.7.0.61
ays-pro Quiz Maker Wordpress<=6.7.0.61
Event History
Sep 22, 2025
CVE Published
via MITRE·06:24 PM
Data Sourced
via MITRE·06:24 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-58014?
CVE-2025-58014 is identified as a critical Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2025-58014?
To fix CVE-2025-58014, you should upgrade Ays Pro Quiz Maker to a version later than 6.7.0.61.
3
What versions are affected by CVE-2025-58014?
CVE-2025-58014 affects Ays Pro Quiz Maker from versions earlier than or equal to 6.7.0.61.
4
Can CVE-2025-58014 impact user data?
Yes, CVE-2025-58014 could potentially allow attackers to perform actions on behalf of users, compromising user data.
5
Is CVE-2025-58014 known to be exploited in the wild?
As of now, there is no specific information indicating that CVE-2025-58014 has been actively exploited in the wild.