Vulnerability Description
The WP-Pro-Quiz WordPress plugin through 0.37 does not have CSRF check in place when deleting a quiz, which could allow an attacker to make a logged in admin delete arbitrary quiz on the blog
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wp-Pro-Quiz Project | Wp-Pro-Quiz | <= 0.37 |
Related Weaknesses (CWE)
References
- https://medium.com/%40hoanhp/0-days-story-1-wp-pro-quiz-2115dd77a6d4
- https://wpscan.com/vulnerability/83679b90-faa5-454e-924c-89f388eccbd1ExploitThird Party Advisory
- https://medium.com/%40hoanhp/0-days-story-1-wp-pro-quiz-2115dd77a6d4
- https://wpscan.com/vulnerability/83679b90-faa5-454e-924c-89f388eccbd1ExploitThird Party Advisory
FAQ
What is CVE-2020-36504?
CVE-2020-36504 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The WP-Pro-Quiz WordPress plugin through 0.37 does not have CSRF check in place when deleting a quiz, which could allow an attacker to make a logged in admin delete arbitrary quiz on the blog
How severe is CVE-2020-36504?
CVE-2020-36504 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-36504?
Check the references section above for vendor advisories and patch information. Affected products include: Wp-Pro-Quiz Project Wp-Pro-Quiz.