Impact
The WordPress Quiz Cat plugin, versions 3.1.1 and earlier, contains an SQL injection vulnerability that allows attackers to inject arbitrary SQL statements when certain input parameters are not properly sanitized. This flaw can lead to unauthorized access to the database, enabling attackers to read, modify, or delete sensitive data stored by the site. The weakness is classified as CWE‑89.
Affected Systems
Affected systems are WordPress sites that have the Fatcatapps Quiz Cat plugin installed at versions 3.1.1 or older. Users who have not upgraded to version 3.2.0 or later remain vulnerable.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity, and while no EPSS score is currently available, the presence of a known SQL injection vector suggests that the likelihood of exploitation is non‑negligible, especially for publicly exposed sites. The plugin is not listed in the CISA KEV catalog, but the vulnerability remains a high‑risk issue because it could compromise the confidentiality and integrity of the site’s data. Attackers would typically exploit the flaw through unfiltered input in the plugin’s parameters, which may be accessible to both authenticated and unauthenticated users depending on configuration.
OpenCVE Enrichment