Impact
Cross‑Site Request Forgery (CSRF) is present in the Ays Pro Quiz Maker WordPress plugin, allowing an attacker to force a compromised or co‑authored user to execute unintended actions within the plugin. The weakness is identified as CWE-352, and although it does not enable direct code execution, it permits unauthorized modification or deletion of quiz settings or content, potentially degrading data integrity and availability.
Affected Systems
The vulnerability affects the Quiz Maker plugin for WordPress released by Ays Pro, any installation of version 6.7.0.82 or earlier. No specific operating system or server platform is limited; any site running the affected WordPress plugin is at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk, and the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires that the victim be authenticated to the site and that the attacker can supply a crafted request, typically via a malicious link or embedded script, which triggers the undesired plugin action.
OpenCVE Enrichment