S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 8, 2024

CVE-2023-0968 Scanner

CVE-2023-0968 scanner - Cross-Site Scripting vulnerability in Watu Quiz

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-0968
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dn’, 'email', 'points', and 'date' parameters in versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Watu Quizby prasunsen
0
Updated Aug 22, 2026View on NVD →
Detail

Watu Quiz is a WordPress plugin developed by Kiboko Labs, designed to create quizzes and surveys for educational, marketing, and entertainment purposes on WordPress sites. It is widely used by educators, marketers, and bloggers to engage with their audience, collect data, and provide interactive content. The plugin allows for the creation of multiple-choice questions, single-answer questions, and essays. It is particularly popular among e-learning platforms and websites looking to add interactive quizzes and surveys to their content. The vulnerability affects versions prior to 3.3.9.1, posing risks to a wide range of websites utilizing this plugin.

The Cross-Site Scripting (XSS) vulnerability in the Watu Quiz plugin before version 3.3.9.1 arises from the plugin's failure to properly sanitize and escape output for several parameters including email, dn, date, and points. This oversight allows attackers to inject malicious scripts into pages, which can then be executed in the context of the user's browser. This particular vulnerability targets high-privilege users, such as administrators, and could lead to the theft of authentication credentials or other attacks.

The flaw is specifically present in the administrative interface of the Watu Quiz plugin, where parameters such as email, dn, date, and points are not properly sanitized or escaped before being displayed back in the page. By crafting a malicious URL that includes these parameters, an attacker can inject and execute arbitrary JavaScript code in the browser of any user who accesses the link, assuming they have the necessary permissions. The vulnerability is exploited through crafted URLs targeting the plugin's quiz results and taking pages.

Exploitation of this vulnerability could lead to several adverse outcomes, including the theft of session cookies, impersonation of privileged users, redirection of users to malicious websites, and potentially further exploitation of the affected site. High-privilege users such as site administrators are particularly at risk, which could compromise the entire WordPress site's security.

By leveraging the security scanning services provided by S4E, users can identify and mitigate vulnerabilities like the one found in the Watu Quiz plugin. Our platform offers comprehensive vulnerability assessments, ensuring your digital assets remain secure against emerging threats. Subscribing to our service not only protects your site from potential exploits but also reinforces your commitment to cybersecurity, thereby maintaining trust with your users and customers.

 

References

Solution Advice
  1. Immediately update the Watu Quiz plugin to version 3.3.9.1 or later.
  2. Regularly update all WordPress plugins, themes, and the core installation to the latest versions.
  3. Utilize security plugins or services that provide web application firewall (WAF) capabilities to block XSS attacks.
  4. Conduct periodic security reviews and vulnerability assessments to detect and remediate potential vulnerabilities.
  5. Educate users with administrative access about the importance of secure practices and caution when handling suspicious links.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-0968 scanner - Cross-Site Scripting vulnerability in Watu Quiz | S4E