CVE-2025-12426 is a sensitive information exposure vulnerability affecting the Quiz Maker plugin for WordPress, versions up to and including 6.7.0.80. This flaw allows unauthenticated attackers to extract quiz answers due to improper authorization checks on the ays_quiz_check_answer AJAX action, where a publicly available nonce is the only validation. With a CVSS score of 7.5 (High), the vulnerability is easily exploitable over the network with low complexity, potentially leading to a complete compromise of quiz answer confidentiality. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.7.0.81CPE matchmatch criteria | cpe:2.3:a:ays-pro:quiz_maker:*:*:*:*:*:wordpress:*:* | ||
>= 0, <= 6.7.0.80CPE match | cpe:2.3:a:ays-pro:quiz_maker:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.