Ays Pro Quiz Maker Business
cpe:2.3:a:ays-pro:quiz_maker:*:*:*:*:wordpress:*:*
- >= 30.0.0, <= 31.8.0
- >= 7.0.0, <= 8.8.0
- >= 20.0.0, <= 21.8.0
A vulnerability allowing unauthenticated users to execute arbitrary shortcodes has been identified in the Quiz Maker WordPress plugin. This issue affects the Business, Developer, and Agency versions of the plugin, all prior to the latest patched releases. The vulnerability arises because the plugin does not properly validate values before executing shortcodes, allowing for unauthorized shortcode execution.
Exploitation of this vulnerability could lead to unauthorized users executing arbitrary shortcodes, potentially allowing them to inject malicious content or execute harmful actions on the WordPress site.
Users are advised to update the Quiz Maker plugin to version 31.8.0.100 for Agency, 21.8.0.100 for Developer, or 8.8.0.100 for Business.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.