Description
Author SQL Injection in Quiz Cat <= 3.1.1 versions.
Published: 2026-09-30
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: SQL Injection (Data Compromise)
Action: Patch Immediately
AI Analysis

Impact

The WordPress Quiz Cat plugin, versions 3.1.1 and earlier, contains an SQL injection vulnerability that allows attackers to inject arbitrary SQL statements when certain input parameters are not properly sanitized. This flaw can lead to unauthorized access to the database, enabling attackers to read, modify, or delete sensitive data stored by the site. The weakness is classified as CWE‑89.

Affected Systems

Affected systems are WordPress sites that have the Fatcatapps Quiz Cat plugin installed at versions 3.1.1 or older. Users who have not upgraded to version 3.2.0 or later remain vulnerable.

Risk and Exploitability

The CVSS score of 7.6 indicates a high severity, and while no EPSS score is currently available, the presence of a known SQL injection vector suggests that the likelihood of exploitation is non‑negligible, especially for publicly exposed sites. The plugin is not listed in the CISA KEV catalog, but the vulnerability remains a high‑risk issue because it could compromise the confidentiality and integrity of the site’s data. Attackers would typically exploit the flaw through unfiltered input in the plugin’s parameters, which may be accessible to both authenticated and unauthenticated users depending on configuration.

Generated by OpenCVE AI on September 30, 2026 at 15:49 UTC.

Remediation

Vendor Solution

Update the WordPress Quiz Cat plugin to the latest available version (at least 3.2.0).


OpenCVE Recommended Actions

  • Upgrade the WordPress Quiz Cat plugin to version 3.2.0 or newer to eliminate the injection flaw.
  • If the plugin is not essential, disable or uninstall it to remove the vulnerable code from the site.
  • Tighten WordPress administrative access by ensuring that only trusted users have editor or administrator roles and consider adding a web application firewall to detect malicious SQL patterns.

Generated by OpenCVE AI on September 30, 2026 at 15:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Author SQL Injection in Quiz Cat <= 3.1.1 versions.
Title WordPress Quiz Cat plugin <= 3.1.1 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T13:27:05.423Z

Reserved: 2026-09-20T00:21:51.841Z

Link: CVE-2026-94082

cve-icon Vulnrichment

Updated: 2026-09-30T13:17:30.317Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T13:17:24.093

Modified: 2026-09-30T14:17:39.247

Link: CVE-2026-94082

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T16:00:15Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')