gist.github.com
https://gist.github.com/Xib3rR4dAr/417a11bcb9b8da28cfe5ba1c17c44d0e CVE-2022-4208
MEDIUM
Chained Quiz <= 1.3.2 - Reflected Cross-Site Scripting via datef
Record summary
CVE-2022-4208 has a selected CVSS score of 6.1 (medium).
Description
The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'datef' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 31, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Chained QuizBrowse prasunsen / Chained QuizDefault status: unaffected | CVE List | Through 1.3.2 | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-4208 plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2824193%40chained-quiz&new=2824193%40chained-quiz&sfp_email=&sfph_mail= wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/5a316c0a-452a-4205-b79b-8bd911016ab2?source=cve wordfence.com
https://www.wordfence.com/vulnerability-advisories-continued