What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz – WordPress Quizzes Builder: from n/a through 1.3.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz – WordPress Quizzes Builder: from n/a through 1.3.0.
Explanation of Vulnerability in Simple Terms
The ARI Stream Quiz plugin for WordPress contains a deserialization vulnerability that allows authenticated users with low privileges to execute arbitrary code on the site. An attacker can craft malicious serialized data that, when processed by the plugin, runs their own PHP code with full site access. This affects all versions up to 1.3.0.
What an attacker can do
Run arbitrary PHP code on the site and take full control of WordPress.
Potential impact on your site
Any logged-in user can compromise the entire WordPress installation and steal or modify all data.
Conditions required to exploit
Attacker must have a low-privilege WordPress account (subscriber or contributor level).
Key dates
External resources
Related vulnerabilities