CVE-2024-10574

HIGH

WordPress Quiz Maker Business/Dev/Agcy <8.8.0/<21.8.0/<31.8.0 - Inf...

Title source: llm
STIX 2.1

Description

The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ays_save_google_credentials' function in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency). This makes it possible for unauthenticated attackers to modify the Google Sheets integration credentials within the plugin's settings. Because the 'client_id' parameter is not sanitized or escaped when used in output, this vulnerability could also be leveraged to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Scores

CVSS v3 7.2
EPSS 0.0045
EPSS Percentile 36.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (3)
AYS Pro Plugins/Quiz Maker Agency < 31.8.0
AYS Pro Plugins/Quiz Maker Business < 8.8.0
AYS Pro Plugins/Quiz Maker Developer < 21.8.0
Published Jan 26, 2025
Tracked Since Feb 18, 2026