Chained Quiz WordPress Plugin Insecure Direct Object Reference Vulnerability

Vulnerability

A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the Chained Quiz plugin for WordPress, affecting versions through 1.3.4. The issue arises from the quiz submission and completion processes, where validation is lacking on a user-controlled key. This vulnerability enables unauthenticated attackers to hijack and modify quiz attempts of other users by manipulating the 'chained_completion_id' cookie. Exploitation of this vulnerability allows attackers to change quiz answers, scores, and results for any user.

Impact

Exploitation of this vulnerability allows for unauthorized modification of quiz attempts, including altering answers, scores, and results.

Reproduction

To reproduce this vulnerability, an unauthenticated user can manipulate the 'chained_completion_id' cookie value to hijack and modify another user's quiz attempt. This can be done by sending a request with the altered cookie value, which the plugin does not properly validate before processing quiz submissions.

Remediation

Users are advised to update the Chained Quiz WordPress plugin to version 1.3.6 or a newer patched version.

Added: Sep 18, 2025, 7:18 AM
Updated: Sep 18, 2025, 2:03 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
1.3
exploitability
7.4
remediation
7.7
relevance
0.5
threat
4.9
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.