CVE-2023-47513
WordPress ARI Stream Quiz – WordPress Quizzes Builder plugin <= 1.3.2 - Content Injection vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in ARI Soft ARI Stream Quiz allows Code Injection.This issue affects ARI Stream Quiz: from n/a through 1.3.2.
Neutralización inadecuada de etiquetas HTML relacionadas con secuencias de comandos en una vulnerabilidad de página web (XSS básico) en ARI Soft ARI Stream Quiz permite la inyección de código. Este problema afecta a ARI Stream Quiz: desde n/a hasta 1.3.2.
The ARI Stream Quiz – WordPress Quizzes Builder plugin for WordPress is vulnerable to content injection due to improper capability checks on the quiz editing functionality in all versions up to, and including, 1.3.2. This makes it possible for authenticated attackers, with contributor access and above, to publish quizzes containing arbitrary content on the site without review.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-11-06 CVE Reserved
- 2023-11-07 CVE Published
- 2024-06-06 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
- CWE-285: Improper Authorization
CAPEC
- CAPEC-242: Code Injection
References (1)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/ari-stream-quiz/wordpress-ari-stream-quiz-wordpress-quizzes-builder-plugin-1-2-32-content-injection-vulnerability?_s_id=cve | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ari Stream Quiz Search vendor "Ari Stream Quiz" | Ari Stream Quiz Search vendor "Ari Stream Quiz" for product "Ari Stream Quiz" | >= 0.0.0 <= 1.3.2 Search vendor "Ari Stream Quiz" for product "Ari Stream Quiz" and version " >= 0.0.0 <= 1.3.2" | en |
Affected
|