Impact
The vulnerability is a missing authorization flaw in the Bob Watu Quiz WordPress plugin that allows an attacker to exploit incorrectly configured access control levels. It is inferred that an unauthorized user could gain elevated access to quiz data and configuration, potentially exposing sensitive information or altering quiz behavior. The weakness is identified as CWE‑862, indicating a lack of proper access control checks.
Affected Systems
The affected product is the Bob Watu Quiz plugin for WordPress, versions 3.4.5 and earlier. Users running any release up to and including 3.4.5 are impacted.
Risk and Exploitability
The CVSS score of 4.3 reflects moderate severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attacks would most likely occur through the web interface of a WordPress site, where an authenticated user with sufficient privileges could exploit the broken access control to perform unauthorized actions.
OpenCVE Enrichment