The plugin does not escape some of its Answers before outputting them in attribute when generating the Quiz, which could lead to Stored Cross-Site Scripting issues
Create or edit a Quiz, and put the following payload as an Answers of a "Multiple Choice: Text" Question: " autofocus onfocus=alert(/XSS/) " Then, the XSS will be triggered when viewing a page with the embed Quiz
Authenticated Stored XSS
Asif Nawaz Minhas
Yes
2021-07-26 (about 10 months ago)
2021-07-26 (about 10 months ago)
2021-08-10 (about 9 months ago)