WordPress Plugin Vulnerabilities
Chained Quiz <= 1.0.8 - Unauthenticated SQL Injection
Description
WordPress Plugin Plugin Chained Quiz before 1.0.9 allows remote unauthenticated users to execute arbitrary SQL commands via the 'answer' and 'answers' parameters.
Technical details:
Chained Quiz appears to be vulnerable to time-based SQL-Injection.
The issue lies on the "$answer" backend variable.
Privileges required: None
Proof of Concept
Affects Plugins
References
Classification
Type
SQLI
OWASP top 10
CWE
CVSS
Miscellaneous
Submitter
Çlirim Emini
Submitter website
Verified
No
WPVDB ID
Timeline
Publicly Published
2018-08-16 (about 7 years ago)
Added
2018-08-17 (about 7 years ago)
Last Updated
2020-09-22 (about 5 years ago)