Impact
The vulnerability is a Cross-Site Request Forgery flaw that allows an attacker to cause an authenticated user of the WordPress Quiz Maker plugin to perform unintended actions. Because the attack can be triggered from a malicious webpage that the user visits while logged into the site, the impact includes unauthorized manipulation of quiz settings, submission of falsified data, or other administrative changes, depending on the actions exposed by the plugin. The weakness is identified as CWE‑352 and does not directly compromise the server or user credentials, but it can lead to unintended behavior within the application.
Affected Systems
The flaw affects the Ays Pro Quiz Maker WordPress plugin versions up to and including 6.7.0.64. Any WordPress site that hosts this plugin and has a user logged in is potentially susceptible.
Risk and Exploitability
The CVSS score of 4.3 places the vulnerability in the moderate range, and the EPSS score of less than 1% indicates a very low probability of exploitation at present. The flaw is not listed in the CISA KEV catalog. It can be exploited by sending a crafted request from a malicious site while a user is authenticated, so the attack vector is essentially web‑browser based and does not require additional vulnerability exploitation.
OpenCVE Enrichment
EUVD