
Cloud Vulnerability DB
A community-led vulnerabilities database
The WP Best Quiz WordPress plugin through version 1.0 contains a Cross-Site Scripting (XSS) vulnerability that affects users with Author-level permissions or higher. The vulnerability was discovered and publicly disclosed on October 28, 2022 (WPScan).
The vulnerability stems from inadequate sanitization and escaping of certain parameters within the plugin. It has been assigned a CVSS score of 4.1 (Medium severity) and is classified under CWE-79. The vulnerability specifically manifests in the Quiz Categories functionality of the plugin (WPScan).
This vulnerability allows authenticated users with Author-level permissions or higher to execute cross-site scripting attacks through the plugin's Quiz Categories feature. When successfully exploited, the XSS payload is triggered when accessing the Add Categories dashboard (WPScan).
As of the latest reports, there is no known fix available for this vulnerability. Users of the WP Best Quiz plugin should consider implementing additional security measures or evaluating alternative quiz plugins until a patch is released (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."