Extension WordPress
Vulnérabilités Quiz Maker Developer
Cette page rassemble les failles publiées pour Quiz Maker Developer, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Quiz Maker Developer
25 fiches
Quiz Maker by AYS <= 6.7.1.29 – Unauthenticated Stored Cross-Site Scripting via 'rate_reason'
The Quiz Maker by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rate_reason' parameter in all versions up to, and including, 6.7.1.29 due to insufficient input sanitization and output escaping. This makes it possible…
*-6.7.1.29
6.7.1.30
01/05/2026
Quiz Maker <= 6.7.1.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `vc_quizmaker` shortcode in all versions up to, and including, 6.7.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This…
*-6.7.1.7
6.7.1.8
19/02/2026
Quiz Maker <= 6.7.1.2 – Cross-Site Request Forgery
The Quiz Maker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.7.1.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers…
*-6.7.1.2
6.7.1.3
10/02/2026
Quiz Maker <= 6.7.0.88 – Authenticated (Admin+) Stored Cross-Site Scripting
The Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.7.0.88 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and…
*-6.7.0.88
6.7.0.89
22/12/2025
Quiz Maker <= 6.7.0.82 – Cross-Site Request Forgery
The Quiz Maker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.7.0.82. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated…
*-6.7.0.82
6.7.0.83
02/12/2025
Quiz Maker <= 6.7.0.80 – Unauthenticated Sensitive Information Exposure
The Quiz Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.7.0.80. This is due to the plugin exposing quiz answers through the ays_quiz_check_answer AJAX action without proper authorization checks.…
*-6.7.0.80
6.7.0.81
18/11/2025
Quiz Maker <= 6.7.0.65 – Unauthenticated Sensitive Information Exposure
The Quiz Maker Business plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.7.0.65. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
*-6.7.0.65
6.7.0.66
22/09/2025
Quiz Maker <= 6.7.0.64 – Cross-Site Request Forgery
The Quiz Maker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.7.0.64. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers…
*-6.7.0.64
6.7.0.65
22/09/2025
Quiz Maker <= 6.7.0.56 – Unauthenticated SQL Injection
The Quiz Maker plugin for WordPress is vulnerable to SQL Injection via spoofed IP headers in all versions up to, and including, 6.7.0.56 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
*-6.7.0.56
6.7.0.57
16/09/2025
Quiz Maker <= 6.6.8.7 – Unauthenticated SQL Injection
The Quiz Maker plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.6.8.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
*-6.6.8.7
6.6.8.8
29/03/2025
Quiz Maker Business, Developer, and Agency <= (Multiple Versions) – Unauthenticated SQL Injection via id
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and…
20.0.0-21.8.0, 30.0.0-31.8.0, 7.0.0-8.8.0
8.8.0.100
25/01/2025
Quiz Maker Business, Developer, and Agency <= (Multiple Versions) – Reflected DOM-Based Cross-Site Scripting via content
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to,…
20.0.0-21.8.0, 30.0.0-31.8.0, 7.0.0-8.8.0
8.8.0.100
25/01/2025
Quiz Maker Business, Developer, and Agency <= (Multiple Versions) – Unauthenticated Arbitrary Shortcode Execution via content
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency).…
20.0.0-21.8.0, 30.0.0-31.8.0, 7.0.0-8.8.0
8.8.0.100
25/01/2025
Quiz Maker Business, Developer, and Agency <= (Multiple Versions) – Missing Authorization to Google Sheets Integration Credentials Modification and Stored Cross-Site Scripting
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ays_save_google_credentials' function in all versions up to, and including, 8.8.0 (Business), up to,…
20.0.0-21.8.0, 30.0.0-31.8.0, 7.0.0-8.8.0
8.8.0.100
25/01/2025
Quiz Maker <= 6.5.9.8 – Authenticated (Admin+) Stored Cross-Site Scripting
The Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-6.5.9.8
6.5.9.9
16/09/2024
Quiz Maker <= 6.5.8.3 – Unauthenticated SQL Injection via 'ays_questions' Parameter
The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-6.5.8.3
6.5.8.4
24/06/2024
Quiz Maker <= 6.5.2.4 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Creation & Modification
The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ays_quick_start() and add_question_rows() functions in all versions up to, and including, 6.5.2.4. This makes it possible for…
*-6.5.2.4
6.5.2.5
06/02/2024
Quiz Maker <= 6.5.2.4 – Missing Authorization to Unauthenticated Quiz Data Retrieval
The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_show_results() function in all versions up to, and including, 6.5.2.4. This makes it possible for unauthenticated attackers…
*-6.5.2.4
6.5.2.5
06/02/2024
Quiz Maker <= 6.5.0.5 – Denial of Service
The Quiz Maker plugin for WordPress is vulnerable to denial of service in all versions up to, and including, 6.5.0.5. The cause is unknown This makes it possible for attackers to potentially deny access to resources.
*-6.5.0.5
6.5.0.6
12/01/2024
Quiz Maker <= 6.5.1.1 – Missing Authorization
The Quiz Maker plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.5.1.1. This makes it possible for authenticated attackers, with subscriber-level access and…
*-6.5.1.1
6.5.1.2
05/01/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.