
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67595 is a Cross-Site Request Forgery (CSRF) vulnerability in the Ays Pro Quiz Maker WordPress plugin. It affects all versions of the plugin through 6.7.0.82 and was published on December 9, 2025, with Patchstack credited as the assigner. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium), requiring no privileges but necessitating user interaction to exploit (Feedly, Patchstack).
The vulnerability is classified under CWE-352 (Cross-Site Request Forgery), meaning the plugin fails to properly validate or enforce anti-CSRF tokens on one or more state-changing requests. An unauthenticated remote attacker can craft a malicious web page or link that, when visited by an authenticated WordPress user (e.g., an administrator), causes the victim's browser to submit unauthorized requests to the Quiz Maker plugin on their behalf. The attack vector is network-based with low complexity, and exploitation requires the victim to interact with attacker-controlled content (Feedly).
Successful exploitation results in a low-integrity impact, allowing an attacker to perform unauthorized actions within the Quiz Maker plugin on behalf of an authenticated user. This could include modifying quiz configurations, deleting quizzes, or altering plugin settings without the victim's knowledge. There is no direct confidentiality or availability impact, and the scope is limited to the affected plugin's functionality (Feedly).
/wp-admin/admin-ajax.php or plugin-specific action URLs) from unusual referrers or external origins.Referer headers pointing to external domains.Users should update the Quiz Maker plugin by Ays Pro to version 6.7.0.83 or later, which addresses this CSRF vulnerability. Until an update can be applied, administrators should avoid clicking on untrusted links while logged into WordPress and consider temporarily deactivating the plugin if it is not in active use. Implementing a web application firewall (WAF) with CSRF protection rules can provide an additional layer of defense (Feedly, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."