WordPress security by component
Quiz Maker
Plugin description
Quiz Maker is a WordPress component with 20 published CVE records in this archive. The latest tracked vulnerability was published Mar 13, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
quiz-makerLatest vulnerability
CVE-2026-32342: Quiz Maker: Cross-site request forgery
Quiz Maker is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
| Safe version |
|
||
|---|---|---|---|
| Mar 13, 2026 |
CVE-2026-32342
Quiz Maker: Cross-site request forgery
Quiz Maker is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Feb 20, 2026 |
CVE-2026-2384
Quiz Maker: Cross-site scripting
Quiz Maker is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jan 12, 2026 |
CVE-2025-14579
Quiz Maker: Cross-site scripting
Quiz Maker is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Dec 09, 2025 |
CVE-2025-67595
Quiz Maker: Cross-site request forgery
Quiz Maker is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Nov 19, 2025 |
CVE-2025-12426
Quiz Maker: Sensitive information exposure
Quiz Maker is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| Sep 22, 2025 |
CVE-2025-58015
Quiz Maker: A security weakness
Quiz Maker is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| Sep 22, 2025 |
CVE-2025-58014
Quiz Maker: Cross-site request forgery
Quiz Maker is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Sep 17, 2025 |
CVE-2025-10042
Quiz Maker: SQL injection
Quiz Maker is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE5.9
NVD7.5
|
| May 15, 2025 |
CVE-2024-8617
Quiz Maker: Cross-site scripting
Quiz Maker is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Apr 01, 2025 |
CVE-2025-30774
Quiz Maker: SQL injection
Quiz Maker is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.2
NVD9.8
|
| Jan 26, 2025 |
CVE-2024-10628
Quiz Maker: SQL injection
Quiz Maker is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Jun 25, 2024 |
CVE-2024-6028
Quiz Maker: SQL injection
Quiz Maker is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Apr 24, 2024 |
CVE-2023-23985
Quiz Maker: A security weakness
Quiz Maker is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE3.7
NVD5.3
|
| Feb 07, 2024 |
CVE-2024-1079
Quiz Maker: A security weakness
Quiz Maker is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Feb 07, 2024 |
CVE-2024-1078
Quiz Maker: A security weakness
Quiz Maker is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Jan 12, 2024 |
CVE-2024-22027
Quiz Maker: A security weakness
Quiz Maker is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2023 |
CVE-2023-6166
Quiz Maker: Cross-site scripting
Quiz Maker is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Dec 26, 2023 |
CVE-2023-6155
Quiz Maker: A security weakness
Quiz Maker is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Jun 05, 2023 |
CVE-2023-2571
Quiz Maker: Cross-site scripting
Quiz Maker is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Aug 02, 2021 |
CVE-2021-24456
Quiz Maker: SQL injection
Quiz Maker is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.2
NVD7.2
|