Impact
The Watu Quiz plugin for WordPress allows unauthenticated attackers to inject malicious scripts into stored data through the HTTP Referer header when the 'Save source URL' feature is enabled. The vulnerability arises from insufficient input sanitization and improper output escaping, enabling the execution of attacker supplied code whenever a user accesses an injected page. This can lead to theft of user credentials, defacement, or session hijacking on the affected site.
Affected Systems
WordPress sites running the Watu Quiz plugin version 3.4.4 or earlier are impacted. The vulnerability is present on installations where the 'Save source URL' option is turned on. No other plugins or WordPress core components are directly affected.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. The EPSS score of less than 1% suggests the likelihood of exploitation is low, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is inferred to be unauthenticated with a crafted HTTP Referer header, requiring an attacker to persuade a user to visit a malicious link. If successful, the attacker can inject web scripts that run in the context of the site, compromising confidentiality, integrity, and availability of user sessions. Combining the severity score, low exploitation probability, and lack of KEV listing, the overall risk is moderate but still warrants remediation.
OpenCVE Enrichment