Impact
The vulnerability originates from missing authorization checks in the Watu Quiz plugin, allowing users with insufficient privileges to bypass configured access controls. The flaw permits an attacker to read or modify quiz data and potentially administrative functions, undermining the confidentiality and integrity of the quiz content. It is classified as a broken access control weakness (CWE-862).
Affected Systems
All installations of Bob Watu Quiz version 3.4.5 or earlier on WordPress sites are affected. No further version granularity is provided, so any instance of the plugin that has not been upgraded to a later release remains vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate risk. The EPSS score of less than 1% shows a very low probability that exploitation is occurring at this time, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely through web application requests to the plugin’s endpoints, where an attacker can submit operations without the required permissions. Although exploitation is currently unlikely, the moderate severity means that unpatched environments should contact the vendor for an update or otherwise limit unauthorized access.
OpenCVE Enrichment