Ays Pro Quiz Maker Business
cpe:2.3:a:ays-pro:quiz_maker:*:*:*:*:wordpress:*:*
- >= 7.0.0, <= 8.8.0
- >= 20.0.0, <= 21.8.0
- >= 30.0.0, <= 31.8.0
A SQL injection vulnerability has been identified in the Quiz Maker Business, Developer, and Agency plugins for WordPress. This issue affects all versions prior to and including 8.8.0 (Business), 21.8.0 (Developer), and 31.8.0 (Agency). The vulnerability arises from inadequate escaping of user-supplied data in the 'id' parameter, allowing unauthenticated attackers to inject additional SQL queries. Exploitation of this vulnerability could lead to unauthorized access to sensitive information in the database.
Successful exploitation allows unauthenticated attackers to execute arbitrary SQL commands, potentially leading to unauthorized data access or manipulation.
The vulnerability can be reproduced by sending a request to the 'wp_ajax_nopriv_ays_questions_statistics_export' endpoint with an injected payload in the 'id' parameter. The injected SQL payload can then be used to extract sensitive information from the database.
Users are advised to update to Quiz Maker Business version 8.8.0.100, Quiz Maker Developer version 21.8.0.100, or Quiz Maker Agency version 31.8.0.100.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.