Vulnerabilities (CVE)

Filtered by vendor Ays-pro Subscribe
Filtered by product Quiz Maker
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6166 1 Ays-pro 1 Quiz Maker 2024-01-02 N/A 6.1 MEDIUM
The Quiz Maker WordPress plugin before 6.4.9.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting
CVE-2023-6155 1 Ays-pro 1 Quiz Maker 2024-01-02 N/A 5.3 MEDIUM
The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticated attacker to perform a search for users of the system, ultimately leaking user email addresses.
CVE-2021-24456 1 Ays-pro 1 Quiz Maker 2021-08-09 6.5 MEDIUM 7.2 HIGH
The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL statements, leading to SQL injection issues in the admin dashboard