CVE-2024-49689 MEDIUM

CVE-2024-49689: WordPress HD Quiz – Save Results Light plugin <= 0.5 - Broken Access Control vulnerability

Vendor Harmonic Design
Product HD Quiz – Save Results Light
Weakness CWE-862 · Missing authorization
Published November 19, 2024
Last update May 11, 2026

CVSS base score

5.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

Missing Authorization vulnerability in Harmonic Design HD Quiz – Save Results Light hd-quiz-save-results-light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HD Quiz – Save Results Light: from n/a through <= 0.5.

Explanation of Vulnerability in Simple Terms

02Summary

HD Quiz – Save Results Light versions 0.5 and earlier lack proper authorization checks on quiz result operations. A logged-in user with low privileges can modify or delete quiz results belonging to other users. The vulnerability requires valid site credentials but no special permissions. Update to a version newer than 0.5 when available.

What an attacker can do

03Attacker Capabilities

Modify or delete quiz results belonging to other users on the site.

Potential impact on your site

04Site Impact

Quiz data integrity is compromised; users' quiz results can be altered or erased by other authenticated users.

Conditions required to exploit

05Prerequisites

Attacker must have a valid user account with low-level site access (e.g., subscriber role).

Key dates

06Disclosure timeline

November 19, 2024 CVE published
May 11, 2026 Record updated

Related vulnerabilities

08Related CVE