CVE-2024-10633
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Jan 26, 2025
CWE ID 95
Summary
CVE-2024-10633 is a vulnerability affecting the Quiz Maker Business, Developer, and Agency plugins for WordPress. Versions up to 8.8.0 for Business, 21.8.0 for Developer, and 31.8.0 for Agency are susceptible. This issue arises due to the plugins permitting the execution of an action without adequately validating user input before running do_shortcode. As a result, unauthenticated attackers can execute arbitrary shortcodes, potentially leading to significant security risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.