Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker quiz-maker allows SQL Injection.This issue affects Quiz Maker: from n/a through <= 6.6.8.7.
Published: 2025-04-01
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Ays Pro Quiz Maker plugin contains an improper neutralization of special elements used in an SQL command that permits an attacker to inject arbitrary SQL statements. This flaw can be exploited to read, modify or delete data stored in the WordPress database, thereby compromising the confidentiality and integrity of site content. The vulnerability is classified as a CWE‑89 SQL Injection.

Affected Systems

Affected systems are WordPress sites that have the Ays Pro Quiz Maker plugin installed, any version through and including 6.6.8.7. The plugin is packaged as the Ays Pro:Quiz Maker WordPress component. If a site has any of these versions, it is subject to the described injection risk.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity. However, the EPSS score of <1% suggests that the likelihood of exploitation is currently very low, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, based on the description implying that an attacker would need to send crafted HTTP requests to the plugin’s endpoints. The observation that the developer’s advisory contains a patch implies that the vulnerability can be mitigated by updating the plugin.

Generated by OpenCVE AI on May 1, 2026 at 12:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Ays Pro Quiz Maker plugin to version 6.6.8.8 or later following the vendor’s patch documentation
  • If updating is not immediately possible, deactivate the plugin or restrict its access to trusted administrators
  • Review the WordPress database user permissions for the plugin and ensure they have the minimum privileges required

Generated by OpenCVE AI on May 1, 2026 at 12:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9108 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker allows SQL Injection. This issue affects Quiz Maker: from n/a through 6.6.8.7.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker allows SQL Injection. This issue affects Quiz Maker: from n/a through 6.6.8.7. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker quiz-maker allows SQL Injection.This issue affects Quiz Maker: from n/a through <= 6.6.8.7.
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 31 Dec 2025 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ays-pro:quiz_maker:*:*:*:*:*:wordpress:*:*

Tue, 01 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 05:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker allows SQL Injection. This issue affects Quiz Maker: from n/a through 6.6.8.7.
Title WordPress Quiz Maker plugin <= 6.6.8.7 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L'}


Subscriptions

Ays-pro Quiz Maker
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:56.891Z

Reserved: 2025-03-26T09:20:01.831Z

Link: CVE-2025-30774

cve-icon Vulnrichment

Updated: 2025-04-01T13:22:29.452Z

cve-icon NVD

Status : Modified

Published: 2025-04-01T06:15:50.623

Modified: 2026-04-23T15:27:02.650

Link: CVE-2025-30774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T12:15:17Z

Weaknesses