← Back

CVE-2024-10628

nvd nist
Published: Jan 26, 2025Modified: Sep 27, 2025

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: security@wordfence.com (Secondary)

Description

The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NOTE: The three variations of this software (Business, Developer, and Agency) share the same plugin slug, so you may get an alert even if you are running the latest version of any of the pieces of software. In these cases it is safe to dismiss the notice once you've confirmed your site is on a patched version of the applicable software.

Affected (3)

Products: Ays Pro: Quiz Maker
1 product
Quiz Maker
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Ays Pro
From 30.0.0 to 31.8.0.100
From 7.0.0 to 8.8.0.100
From 20.0.0 to 21.8.0.100

References (5)

Source: security@wordfence.com
ExploitThird Party Advisory
Source: security@wordfence.com
Product
Source: security@wordfence.com
Product
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitThird Party Advisory

Timeline

No history available yet.