Impact
The Bob Chained Quiz plugin contains a Server Side Request Forgery (SSRF) flaw, classified as CWE‑918. The vulnerability enables an external attacker to manipulate the plugin’s outbound requests, causing the vulnerable host to fetch data from arbitrary internal or external URLs. This can lead to information disclosure, internal network reconnaissance, or further exploitation of downstream services.
Affected Systems
Products affected include the Bob Chained Quiz WordPress plugin Version 1.3.2.9 and all earlier releases. The flaw is present in all builds up through version 1.3.2.9, with no known fixes released for those specific versions.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate severity, while the EPSS score of less than 1% shows a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet been widely exploited. Attackers would need to manipulate the plugin’s input parameters to trigger the SSRF; no remote code execution or privilege escalation is implied by the description. Overall risk is moderate, but remediation is advised to prevent potential internal data exfiltration or service disruption.
OpenCVE Enrichment
EUVD