Kibokolabs Watu Quiz vulnerabilities

12 known vulnerabilities affecting kibokolabs/watu_quiz.

Total CVEs
12
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM10

Vulnerabilities

Page 1 of 1
CVE-2025-46242MEDIUMCVSS 4.9fixed in 3.4.42025-04-22
CVE-2025-46242 [MEDIUM] CWE-89 CVE-2025-46242: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Watu Quiz watu allows SQL Injection.This issue affects Watu Quiz: from n/a through <= 3.4.3.
nvd
CVE-2025-30844MEDIUMCVSS 6.1fixed in 3.4.32025-04-01
CVE-2025-30844 [MEDIUM] CWE-79 CVE-2025-30844: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Watu Quiz watu allows Reflected XSS.This issue affects Watu Quiz: from n/a through <= 3.4.2.
nvd
CVE-2024-53792HIGHCVSS 8.8fixed in 3.4.32024-12-02
CVE-2024-53792 [HIGH] CWE-89 CVE-2024-53792: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Watu Quiz watu allows SQL Injection.This issue affects Watu Quiz: from n/a through <= 3.4.1.2.
nvd
CVE-2024-2640MEDIUMCVSS 5.4fixed in 3.4.1.22024-07-12
CVE-2024-2640 [MEDIUM] CWE-79 CVE-2024-2640: The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, whi The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, which could allow users such as authors (if they've been authorized by admins) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
nvd
CVE-2024-0873MEDIUMCVSS 5.4fixed in 3.4.1.12024-04-09
CVE-2024-0873 [MEDIUM] CWE-79 CVE-2024-0873: The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wa The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'watu-basic-chart' shortcode in all versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions
nvd
CVE-2024-0872MEDIUMCVSS 4.3fixed in 3.4.1.12024-04-09
CVE-2024-0872 [MEDIUM] CWE-639 CVE-2024-0872: The Watu Quiz plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u The Watu Quiz plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.1 via the watu-userinfo shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive user meta data which can include session tokens and user emails.
nvd
CVE-2023-30483MEDIUMCVSS 6.1≤ 3.3.9.22023-08-14
CVE-2023-30483 [MEDIUM] CWE-79 CVE-2023-30483: Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Watu Quiz plugin <= 3.3.9. Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Watu Quiz plugin <= 3.3.9.2 versions.
nvd
CVE-2015-10111CRITICALCVSS 9.8fixed in 2.6.82023-06-04
CVE-2015-10111 [CRITICAL] CWE-89 CVE-2015-10111: A vulnerability was found in Watu Quiz Plugin up to 2.6.7 on WordPress. It has been rated as critica A vulnerability was found in Watu Quiz Plugin up to 2.6.7 on WordPress. It has been rated as critical. This issue affects the function watu_exams of the file controllers/exam.php of the component Exam Handler. The manipulation of the argument quiz leads to sql injection. The attack may be initiated remotely. Upgrading to version 2.6.8 is able to ad
nvd
CVE-2023-25022MEDIUMCVSS 4.8≤ 3.3.82023-04-07
CVE-2023-25022 [MEDIUM] CWE-79 CVE-2023-25022: Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Watu Quiz plugin <= 3. Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Watu Quiz plugin <= 3.3.8 versions.
nvd
CVE-2023-0968MEDIUMCVSS 6.1PoC≤ 3.3.92023-03-03
CVE-2023-0968 [MEDIUM] CWE-79 CVE-2023-0968: The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dn’, 'em The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dn’, 'email', 'points', and 'date' parameters in versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they c
nvd
CVE-2023-0428MEDIUMCVSS 6.1fixed in 3.3.8.22023-02-21
CVE-2023-0428 [MEDIUM] CWE-79 CVE-2023-0428: The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape a parameter before output The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
nvd
CVE-2023-0429MEDIUMCVSS 4.8fixed in 3.3.8.22023-02-21
CVE-2023-0429 [MEDIUM] CWE-79 CVE-2023-0429: The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape some of its settings, whi The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
nvd