Impact
The vulnerability in the WordPress Quiz Maker plugin allows an attacker to retrieve embedded sensitive data from the plugin. It is a CWE‑497 flaw that permits an unauthorized control sphere to read information that should be protected. The exposed data may include any sensitive system information stored or displayed by the plugin, leading to potential disclosure of confidential information.
Affected Systems
Ays Pro:Quiz Maker is affected in all releases up to and including version 6.7.0.65. The plugin operates within the WordPress ecosystem, so any WordPress site that has an affected instance of Quiz Maker is vulnerable. No other operating system or server configuration constraints are specified.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of <1% shows a low exploitation probability at the present time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, with an unauthenticated attacker making HTTP requests to the plugin’s endpoints or configuration pages to extract sensitive data. No authentication or privilege escalation is required, making the attack relatively straightforward for an adversary who can reach the site.
OpenCVE Enrichment
EUVD