What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in WePupil Quiz Expert plugin <= 1.5.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in WePupil Quiz Expert plugin <= 1.5.0 versions.
Explanation of Vulnerability in Simple Terms
Quiz Expert versions up to 1.5.0 contain a cross-site request forgery (CSRF) vulnerability that allows attackers to perform unauthorized actions on behalf of site visitors. An attacker can craft a malicious link or page that, when visited by a logged-in user, triggers unwanted changes to quiz settings or data. The vulnerability requires user interaction and does not expose sensitive information directly.
What an attacker can do
Perform unauthorized actions on the site by tricking a logged-in user into visiting a malicious page.
Potential impact on your site
Quiz settings or data could be modified without your knowledge if users are tricked into visiting malicious pages.
Conditions required to exploit
A site visitor must be logged in and click a malicious link or visit an attacker-controlled page.
Key dates
External resources
Related vulnerabilities