Severity
5.3MEDIUM
EPSS
0.4%
top 36.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 26

Description

The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticated attacker to perform a search for users of the system, ultimately leaking user email addresses.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5unknown/quiz_maker< 6.4.9.5
NVDays-pro/quiz_maker< 6.4.9.5

🔴Vulnerability Details

2
GHSA
GHSA-92jj-pmcg-vv48: The Quiz Maker WordPress plugin before 62023-12-26
CVEList
Quiz Maker < 6.4.9.5 - Unauthenticated Email Address Disclosure2023-12-26
CVE-2023-6155 (MEDIUM CVSS 5.3) | The Quiz Maker WordPress plugin bef | cvebase.io