Impact
This vulnerability is a missing authorization flaw in Harmonic Design's HD Quiz plugin for WordPress. It allows an unauthenticated attacker to bypass configured security levels and gain access to functions normally restricted to administrator users. The flaw is classified as a broken access control weakness (CWE-862) and could lead to unauthorized modification of quiz content or settings, potentially leaking sensitive data.
Affected Systems
WordPress sites that have Harmonic Design's HD Quiz plugin installed and activated are affected. All versions of the plugin up to and including 2.0.9 are vulnerable; versions newer than 2.0.9 are not affected.
Risk and Exploitability
The CVSS score of 4.3 indicates a low‑to‑moderate impact. The EPSS score of less than 1% suggests a very low probability of exploitation, and the vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that the attack vector relies on accessing the plugin’s administrative URLs over HTTP or HTTPS, but this detail is not explicitly confirmed in the advisory.
OpenCVE Enrichment