CVE-2024-8617Cross-site Scripting in Quiz Maker

Severity
4.8MEDIUMNVD
EPSS
0.2%
top 62.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 15

Description

The Quiz Maker WordPress plugin before 6.5.9.9 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages1 packages

NVDays-pro/quiz_maker< 6.5.9.9

🔴Vulnerability Details

2
GHSA
GHSA-9mpf-r669-m5wq: The Quiz Maker WordPress plugin before 62025-05-15
CVEList
Quiz Maker <= 6.5.9.8 - Admin+ Stored XSS2025-05-15

📋Vendor Advisories

1
Red Hat
kernel: sctp: set sk_state back to CLOSED if autobind fails in sctp_listen_start2024-10-21
CVE-2024-8617 — Cross-site Scripting in Quiz Maker | cvebase