Quiz And Survey Master <= 8.1.10 - Excessive Quiz Attempts

2023-07-17 00:00
qilin_99

Strategic Overview

Vulnerability Overview

The Quiz And Survey Master plugin for WordPress is vulnerable to exessive quiz attempts due to a missing validation checks on the ajax_submit_results() function in versions up to, and including, 8.1.10. This makes it possible for unauthenticated attackers to bypass the set limits for the number of times a user can attempt a quiz.

Technical Analysis

REMEDIATION: Update to version 8.1.11, or a newer patched version --- IDENTIFIER: CWE-799 (Improper Control of Interaction Frequency) The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C