nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-4213 CVE-2022-4213
MEDIUM
Chained Quiz <= 1.3.2.2 - Reflected Cross-Site Scripting via dn
Record summary
CVE-2022-4213 has a selected CVSS score of 6.1 (medium).
Description
The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dn' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 31, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Chained QuizBrowse prasunsen / Chained QuizDefault status: unaffected | CVE List | Through 1.3.2.2 | affected |
References
4plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2825368%40chained-quiz&new=2825368%40chained-quiz&sfp_email=&sfph_mail= wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/d46edcfe-ab6b-4966-9d85-40a2e2ee3d44?source=cve wordfence.com
https://www.wordfence.com/vulnerability-advisories-continued