Impact
The Ays Pro Quiz Maker plugin contains an improper neutralization of special elements used in an SQL command that permits an attacker to inject arbitrary SQL statements. This flaw can be exploited to read, modify or delete data stored in the WordPress database, thereby compromising the confidentiality and integrity of site content. The vulnerability is classified as a CWE‑89 SQL Injection.
Affected Systems
Affected systems are WordPress sites that have the Ays Pro Quiz Maker plugin installed, any version through and including 6.6.8.7. The plugin is packaged as the Ays Pro:Quiz Maker WordPress component. If a site has any of these versions, it is subject to the described injection risk.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity. However, the EPSS score of <1% suggests that the likelihood of exploitation is currently very low, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, based on the description implying that an attacker would need to send crafted HTTP requests to the plugin’s endpoints. The observation that the developer’s advisory contains a patch implies that the vulnerability can be mitigated by updating the plugin.
OpenCVE Enrichment
EUVD