Input validation vulnerability in Chained Quiz 1.3.2.3

The Chained Quiz plugin for WordPress is not secure in versions up to 1.3.2.3. This means that malicious people can inject code into pages that can be executed if they can get a user to click a link. This is done by using the ‘ip’ parameter on the ‘chainedquiz_list’ page without proper input sanitization and output escaping.

Detected in:

Chained Quiz fixed vulnerable versions: >= * <= 1.3.2.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.