CVE-2024-0872Authorization Bypass Through User-Controlled Key in Watu Quiz

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 51.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 9

Description

The Watu Quiz plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.1 via the watu-userinfo shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive user meta data which can include session tokens and user emails.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVDkibokolabs/watu_quiz< 3.4.1.1
CVEListV5prasunsen/watu_quiz3.4.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-49pj-m3ff-pg2m: The Watu Quiz plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 32024-04-09
CVEList
Watu Quiz <= 3.4.1 - Sensitive Information Disclosure2024-04-09
CVE-2024-0872 — Kibokolabs Watu Quiz vulnerability | cvebase