Input validation vulnerability in ARI Stream Quiz – WordPress Quizzes Builder 1.3.0

The ARI Stream Quiz – WordPress Quizzes Builder is a plugin for WordPress websites, but it has a vulnerability that could allow malicious attackers to gain access to the website. This vulnerability, known as PHP Object Injection, is present in all versions of the plugin up to 1.3.0. It means that if someone with contributor access or higher is able to exploit this vulnerability, they can inject a malicious object into the website. This object could be used to delete files, steal sensitive information, or execute code. It is important to note that the vulnerable plugin does not have a POP chain, but if a POP chain is present on the website through another plugin or theme, then it could be used to further take advantage of the vulnerability.

Detected in:

ARI Stream Quiz – WordPress Quizzes Builder open vulnerable versions: >= * <= 1.3.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.