CVE Database
/

CVE-2023-6155

Back to search

CVE-2023-6155

Published: Dec 26, 2023

Modified: Sep 12, 2024

PUBLISHED

Description

The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticated attacker to perform a search for users of the system, ultimately leaking user email addresses.

VendorProductVersions

Unknown

Quiz Maker

affected
0 - < 6.4.9.5

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now