Quiz Maker by AYS

33 known CVEs 20K+ active installs

Scan My Site Free

UNKNOWN: 33
Known Vulnerabilities 33
CVE-2026-2384 UNKNOWN EPSS 0.1%
Published 2026-02-20 · Affected: *
The Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `vc_quizmaker` shortcode in all versions up to, and including, 6.7.1.7 due to insufficient input sanit
CVE-2025-67595 UNKNOWN
Published 2025-12-09 · Affected: *
Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Quiz Maker quiz-maker allows Cross Site Request Forgery.This issue affects Quiz Maker: from n/a through <= 6.7.0.82.
CVE-2025-67595 UNKNOWN
Published 2025-12-09 · Affected: *
Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Quiz Maker quiz-maker allows Cross Site Request Forgery.This issue affects Quiz Maker: from n/a through <= 6.7.0.82.
CVE-2025-67595 UNKNOWN
Published 2025-12-09 · Affected: *
Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Quiz Maker quiz-maker allows Cross Site Request Forgery.This issue affects Quiz Maker: from n/a through <= 6.7.0.82.
CVE-2025-67595 UNKNOWN
Published 2025-12-09 · Affected: *
Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Quiz Maker quiz-maker allows Cross Site Request Forgery.This issue affects Quiz Maker: from n/a through <= 6.7.0.82.
CVE-2025-12426 UNKNOWN EPSS 0.3%
Published 2025-11-19 · Affected: *
The Quiz Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.7.0.80. This is due to the plugin exposing quiz answers through the ays_quiz
CVE-2025-58015 UNKNOWN EPSS 0.3%
Published 2025-09-22 · Affected: *
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Ays Pro Quiz Maker quiz-maker allows Retrieve Embedded Sensitive Data.This issue affects Quiz Maker: from n/
CVE-2025-58015 UNKNOWN EPSS 0.3%
Published 2025-09-22 · Affected: *
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Ays Pro Quiz Maker quiz-maker allows Retrieve Embedded Sensitive Data.This issue affects Quiz Maker: from n/
CVE-2025-58015 UNKNOWN EPSS 0.3%
Published 2025-09-22 · Affected: *
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Ays Pro Quiz Maker quiz-maker allows Retrieve Embedded Sensitive Data.This issue affects Quiz Maker: from n/
CVE-2025-58015 UNKNOWN EPSS 0.3%
Published 2025-09-22 · Affected: *
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Ays Pro Quiz Maker quiz-maker allows Retrieve Embedded Sensitive Data.This issue affects Quiz Maker: from n/
CVE-2025-58015 UNKNOWN EPSS 0.3%
Published 2025-09-22 · Affected: *
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Ays Pro Quiz Maker quiz-maker allows Retrieve Embedded Sensitive Data.This issue affects Quiz Maker: from n/
CVE-2025-58014 UNKNOWN
Published 2025-09-22 · Affected: *
Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Quiz Maker quiz-maker allows Cross Site Request Forgery.This issue affects Quiz Maker: from n/a through <= 6.7.0.64.
CVE-2025-58014 UNKNOWN
Published 2025-09-22 · Affected: *
Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Quiz Maker quiz-maker allows Cross Site Request Forgery.This issue affects Quiz Maker: from n/a through <= 6.7.0.64.
CVE-2025-58014 UNKNOWN
Published 2025-09-22 · Affected: *
Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Quiz Maker quiz-maker allows Cross Site Request Forgery.This issue affects Quiz Maker: from n/a through <= 6.7.0.64.
CVE-2025-58014 UNKNOWN
Published 2025-09-22 · Affected: *
Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Quiz Maker quiz-maker allows Cross Site Request Forgery.This issue affects Quiz Maker: from n/a through <= 6.7.0.64.
CVE-2025-58014 UNKNOWN
Published 2025-09-22 · Affected: *
Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Quiz Maker quiz-maker allows Cross Site Request Forgery.This issue affects Quiz Maker: from n/a through <= 6.7.0.64.
CVE-2025-10042 UNKNOWN EPSS 0.6%
Published 2025-09-17 · Affected: *
The Quiz Maker plugin for WordPress is vulnerable to SQL Injection via spoofed IP headers in all versions up to, and including, 6.7.0.56 due to insufficient escaping on the user supplied parameter and
CVE-2025-30774 UNKNOWN EPSS 0.3%
Published 2025-04-01 · Affected: *
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker quiz-maker allows SQL Injection.This issue affects Quiz Maker: from n/a through
CVE-2025-30774 UNKNOWN EPSS 0.3%
Published 2025-04-01 · Affected: *
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker quiz-maker allows SQL Injection.This issue affects Quiz Maker: from n/a through
CVE-2025-30774 UNKNOWN EPSS 0.3%
Published 2025-04-01 · Affected: *
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker quiz-maker allows SQL Injection.This issue affects Quiz Maker: from n/a through
CVE-2025-30774 UNKNOWN EPSS 0.3%
Published 2025-04-01 · Affected: *
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker quiz-maker allows SQL Injection.This issue affects Quiz Maker: from n/a through
CVE-2025-30774 UNKNOWN EPSS 0.3%
Published 2025-04-01 · Affected: *
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker quiz-maker allows SQL Injection.This issue affects Quiz Maker: from n/a through
CVE-2025-30774 UNKNOWN EPSS 0.3%
Published 2025-04-01 · Affected: *
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker quiz-maker allows SQL Injection.This issue affects Quiz Maker: from n/a through
CVE-2024-6028 UNKNOWN EPSS 1.0%
Published 2024-06-25 · Affected: *
The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient escaping on the user s
CVE-2024-6028 UNKNOWN EPSS 1.0%
Published 2024-06-25 · Affected: *
The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient escaping on the user s
CVE-2024-6028 UNKNOWN EPSS 1.0%
Published 2024-06-25 · Affected: *
The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient escaping on the user s
CVE-2024-6028 UNKNOWN EPSS 1.0%
Published 2024-06-25 · Affected: *
The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient escaping on the user s
CVE-2023-23985 UNKNOWN EPSS 0.3%
Published 2024-04-24 · Affected: *
Missing Authorization vulnerability in Quiz Maker team Quiz Maker.This issue affects Quiz Maker: from n/a through 6.3.9.4.
CVE-2023-23985 UNKNOWN EPSS 0.3%
Published 2024-04-24 · Affected: *
Missing Authorization vulnerability in Quiz Maker team Quiz Maker.This issue affects Quiz Maker: from n/a through 6.3.9.4.
CVE-2024-1079 UNKNOWN EPSS 0.4%
Published 2024-02-07 · Affected: *
The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_show_results() function in all versions up to, and including, 6.5.2.4. Thi
CVE-2024-1079 UNKNOWN EPSS 0.4%
Published 2024-02-07 · Affected: *
The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_show_results() function in all versions up to, and including, 6.5.2.4. Thi
CVE-2024-1078 UNKNOWN EPSS 0.3%
Published 2024-02-07 · Affected: *
The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ays_quick_start() and add_question_rows() functions in all versions up t
CVE-2024-1078 UNKNOWN EPSS 0.3%
Published 2024-02-07 · Affected: *
The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ays_quick_start() and add_question_rows() functions in all versions up t

Is Quiz Maker by AYS running on your site?

A free scan detects your plugins and flags any that match these CVEs.

Scan My Site Free