PT-2026-53042 · WordPress · Hd Quiz
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
HD Quiz versions 2.2.0 through 2.2.1
Description
The HD Quiz plugin for WordPress contains a Cross-Site Request Forgery (CSRF) flaw. This occurs because the
hdq validate nonce() function fails to properly validate nonces, which are unique tokens used to prevent unauthorized requests. Consequently, unauthenticated attackers can trick a site administrator into clicking a malicious link to execute forged requests. This allows the attacker to create new quizzes, modify or delete existing quizzes and questions, and alter plugin settings.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hd Quiz