Impact
The Ultimate Viral Quiz plugin for WordPress contains a flawed nonce validation in the thesave_options() function. Because the nonce check is missing or incorrect, an attacker can craft a request that updates the plugin’s configuration settings. This flaw allows an unauthenticated actor to modify settings without logging into the WordPress site, potentially altering how the plugin behaves and affecting site functionality.
Affected Systems
All released versions of the Ultimate Viral Quiz plugin from the vendor hameha up to and including 1.0 are impacted. Site administrators running any of these versions risk having their configuration altered if they visit a malicious link that triggers the settings update.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score is less than 1%, suggesting a low likelihood of widespread exploitation at present. The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can exploit this by convincing an administrator to click an attacker‑controlled link that submits a forged request; no additional privileges or system access are required beyond the administrator’s session.
OpenCVE Enrichment
EUVD