Extension WordPress
Vulnérabilités Chained Quiz
Cette page rassemble les failles publiées pour Chained Quiz, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Chained Quiz
24 fiches
Chained Quiz <= 1.3.5 – Unauthenticated Insecure Direct Object Reference via Cookie
The Chained Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference in version 1.3.4 and below via the quiz submission and completion mechanisms due to missing validation on a user controlled key. This makes it possible…
*-1.3.5
1.3.6
17/09/2025
Chained Quiz <= 1.3.2.9 – Authenticated (Admin+) Server-Side Request Forgery
The Chained Quiz plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.2.9. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary…
*-1.3.2.9
1.3.3
24/01/2025
Chained Quiz <= 1.3.2.8 – Missing Authorization
The Chained Quiz plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the finalize() function in all versions up to, and including, 1.3.2.8. This makes it possible for unauthenticated attackers to answer…
*-1.3.2.8
1.3.2.9
09/07/2024
Chained Quiz <= 1.3.2.8 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and…
*-1.3.2.8
1.3.2.9
28/06/2024
Chained Quiz <= 1.3.2.5 – Authenticated (Admin+) Stored Cross-Site Scripting
The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions, to…
*-1.3.2.5
1.3.2.6
06/02/2023
Chained Quiz <= 1.3.2.2 – Reflected Cross-Site Scripting via dn
The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dn' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2.2 due to insufficient input sanitization and output escaping. This makes it…
*-1.3.2.2
1.3.2.3
02/12/2022
Chained Quiz <= 1.3.2.4 – Cross-Site Request Forgery to Submitted Response Deletion
The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4. This is due to missing nonce validation on the manage() function. This makes it possible for unauthenticated attackers to…
*-1.3.2.4
1.3.2.5
02/12/2022
Chained Quiz <= 1.3.2 – Reflected Cross-Site Scripting via dnf
The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dnf' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it…
*-1.3.2
1.3.2.1
02/12/2022
Chained Quiz <= 1.3.2.2 – Authenticated (Admin+) Stored Cross-Site Scripting via Facebook App ID
The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'facebook_appid' parameter in versions up to, and including, 1.3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers…
*-1.3.2.2
1.3.2.3
02/12/2022
Chained Quiz <= 1.3.2 – Reflected Cross-Site Scripting via pointsf
The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pointsf' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it…
*-1.3.2
1.3.2.1
02/12/2022
Chained Quiz <= 1.3.2.3 – Reflected Cross-Site Scripting via date
The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2.3 due to insufficient input sanitization and output escaping. This makes it…
*-1.3.2.3
1.3.2.4
02/12/2022
Chained Quiz <= 1.3.2 – Reflected Cross-Site Scripting via ipf
The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ipf' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it…
*-1.3.2
1.3.2.1
02/12/2022
Chained Quiz <= 1.3.2.4 – Cross-Site Request Forgery to Question Deletion
The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4. This is due to missing nonce validation on the list_questions() function. This makes it possible for unauthenticated attackers to…
*-1.3.2.4
1.3.2.5
02/12/2022
Chained Quiz <= 1.3.2.2 – Authenticated (Admin+) Stored Cross-Site Scripting via Mailchimp API Key
The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key' parameter in versions up to, and including, 1.3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers…
*-1.3.2.2
1.3.2.3
02/12/2022
Chained Quiz <= 1.3.2.3 – Reflected Cross-Site Scripting via ip
The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ip' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2.3 due to insufficient input sanitization and output escaping. This makes it…
*-1.3.2.3
1.3.2.4
02/12/2022
Chained Quiz <= 1.3.2 – Reflected Cross-Site Scripting via emailf
The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'emailf' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it…
*-1.3.2
1.3.2.1
02/12/2022
Chained Quiz <= 1.3.2 – Reflected Cross-Site Scripting via datef
The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'datef' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it…
*-1.3.2
1.3.2.1
02/12/2022
Chained Quiz <= 1.3.2.4 – Cross-Site Request Forgery to Arbitrary Quiz Deletion and Copying
The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4. This is due to missing nonce validation on the list_quizzes() function. This makes it possible for unauthenticated attackers to…
*-1.3.2.4
1.3.2.5
02/12/2022
Chained Quiz < 1.2.7.2 – Cross-Site Scripting
The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings.
[*, 1.2.7.2)
1.2.7.2
07/09/2021
Chained Quiz <= 1.1.9 -Stored Cross-Site Scripting
The Chained Quiz for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘chained_admin_subject', 'chained_user_subject', 'chained_sender_name', 'chained_sender_email' and 'go_ahead_value' values in versions up to, and including, 1.1.9.0 due to insufficient input sanitization and output escaping. This makes it…
*-1.1.9
1.1.9.1
21/02/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.