Impact
Missing authorization vulnerability in fatcatapps Quiz Cat plugin 3.0.8 and earlier allows an attacker to bypass the plugin's access control checks because the plugin does not verify a user’s role before granting access to quiz management functions. As a result, an unauthenticated or low‑privileged user can read, modify or delete quiz content, potentially exposing sensitive information or disrupting the quiz workflow. The flaw is a classic example of a missing authorization error (CWE‑862) and is particularly dangerous for sites that rely on the plugin for public quizzes or for sensitive educational content.
Affected Systems
Fatcatapps Quiz Cat plugin v3.0.8 and earlier are affected on any WordPress installation that has the plugin activated. No other plugins or WordPress core components are known to be impacted.
Risk and Exploitability
The CVSS score of 2.7 indicates a low‑to‑moderate severity, and the EPSS score of <1% suggests a very low probability of exploitation at this time. The flaw is not listed in the CISA KEV catalog, which further supports that it is not a known widely exploited vulnerability. The likely attack vector is through HTTP requests to the plugin’s administration endpoints, allowing an attacker to craft requests that trigger the missing authorization check.
OpenCVE Enrichment
EUVD