PT-2024-16909 · WordPress · Ai Quiz | Quiz Maker

·

CVE-2024-11323

·

Published

2024-12-06

·

Updated

2024-12-11

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AI Quiz | Quiz Maker plugin for WordPress versions up to, and including, 1.1
Description The issue allows unauthorized modification of data, leading to privilege escalation due to a missing capability check on the ai quiz update style() function. This enables authenticated attackers with Subscriber-level access and above to update arbitrary options on the WordPress site, potentially gaining administrative user access.
Recommendations For AI Quiz | Quiz Maker plugin for WordPress versions up to, and including, 1.1, update the plugin to a version that includes the necessary capability checks to prevent unauthorized data modification. As a temporary workaround, consider disabling the ai quiz update style() function until a patch is available. Restrict access to the plugin's functionality to minimize the risk of exploitation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-11323

Affected Products

Ai Quiz | Quiz Maker