CVE-2026-94082: WordPress Quiz Cat plugin <= 3.1.1 - SQL Injection vulnerability
Published Sep 30, 2026
·Updated
Author SQL Injection in Quiz Cat <= 3.1.1 versions.
Affected Software
1 affected component
Quiz Cat Quiz Cat<=3.1.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Quiz Cat pluginto a version that resolves this vulnerability.Fixed in 3.2.0
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attack requires high privileges (PR:H). It is remotely exploitable over the network, has low attack complexity, and does not require user interaction.
2
What are the potential impacts if exploitation succeeds?
The vulnerability can expose confidential information and cause limited availability impact. The scope is changed (S:C), meaning the impact may extend beyond the vulnerable component's security authority.
3
Which installations should be treated as affected?
Quiz Cat versions 3.1.1 and earlier are identified as affected. The provided information does not state whether a fixed version or workaround is available.