Quiz Maker
Vendor:
First CVE: Aug 2, 2021 · Active for 4 years
19
Total CVEs
More Total CVEs than 95% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 30% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Quiz Maker over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 2, 2021
4 years ago
Most Recent CVE
Mar 13, 2026
137 days ago
CVE Severity & Scoring
Quiz Maker19 CVEs
63%
26%
11%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (68.4%)
Unknown0 (0.0%)
Required6 (31.6%)
Privileges Required
Low3 (15.8%)
High2 (10.5%)
None14 (73.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6028CRITICAL The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient es | Jun 25, 2024 | 9.8 | 46 | NO | YES |
CVE-2025-10042HIGH The Quiz Maker plugin for WordPress is vulnerable to SQL Injection via spoofed IP headers in all versions up to, and including, 6.7.0.56 due to insufficient escaping on the user su | Sep 17, 2025 | 7.5 | 37 | NO | YES |
CVE-2025-30774CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker quiz-maker allows SQL Injection.This issue affects Quiz Mak | Apr 1, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-12426HIGH The Quiz Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.7.0.80. This is due to the plugin exposing quiz answers | Nov 19, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-58015HIGH Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Ays Pro Quiz Maker quiz-maker allows Retrieve Embedded Sensitive Data.This issue affects | Sep 22, 2025 | 7.5 | 24 | NO | NO |
CVE-2024-10628HIGH The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 8.8.0 (Business), u | Jan 26, 2025 | 7.5 | 24 | NO | NO |
CVE-2021-24456HIGH The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL statements, leading to SQL injection i | Aug 2, 2021 | 7.2 | 22 | NO | NO |
CVE-2026-2384MEDIUM The Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `vc_quizmaker` shortcode in all versions up to, and including, 6.7.1.7 due to insu | Feb 20, 2026 | 6.4 | 21 | NO | NO |
CVE-2024-22027MEDIUM Improper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a remote authenticated attacker to perform a Denial of Service (DoS) attack against e | Jan 12, 2024 | 6.5 | 20 | NO | NO |
CVE-2023-6166MEDIUM The Quiz Maker WordPress plugin before 6.4.9.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting | Dec 26, 2023 | 6.1 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
5.3% of CVEs· 97th percentile
ExploitDB
1 CVE
5.3% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Quiz Maker
Top CWEs
Versions
No cataloged versions.