CVE-2025-30774

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker quiz-maker allows SQL Injection.This issue affects Quiz Maker: from n/a through <= 6.6.8.7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ays-pro:quiz_maker:*:*:*:*:*:wordpress:*:*

History

23 Apr 2026, 15:27

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 8.2

01 Apr 2026, 17:20

Type Values Removed Values Added
Summary (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker allows SQL Injection. This issue affects Quiz Maker: from n/a through 6.6.8.7. (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker quiz-maker allows SQL Injection.This issue affects Quiz Maker: from n/a through <= 6.6.8.7.
References
  • {'url': 'https://patchstack.com/database/wordpress/plugin/quiz-maker/vulnerability/wordpress-quiz-maker-plugin-6-6-8-7-sql-injection-vulnerability?_s_id=cve', 'tags': ['Third Party Advisory'], 'source': 'audit@patchstack.com'}
  • () https://patchstack.com/database/Wordpress/Plugin/quiz-maker/vulnerability/wordpress-quiz-maker-plugin-6-6-8-7-sql-injection-vulnerability?_s_id=cve - Third Party Advisory
CVSS v2 : unknown
v3 : 8.2
v2 : unknown
v3 : 9.8

31 Dec 2025, 16:58

Type Values Removed Values Added
References () https://patchstack.com/database/wordpress/plugin/quiz-maker/vulnerability/wordpress-quiz-maker-plugin-6-6-8-7-sql-injection-vulnerability?_s_id=cve - () https://patchstack.com/database/wordpress/plugin/quiz-maker/vulnerability/wordpress-quiz-maker-plugin-6-6-8-7-sql-injection-vulnerability?_s_id=cve - Third Party Advisory
Summary
  • (es) La vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ('Inyección SQL') en Ays Pro Quiz Maker permite la inyección SQL. Este problema afecta a Quiz Maker desde n/d hasta la versión 6.6.8.7.
First Time Ays-pro quiz Maker
Ays-pro
CPE cpe:2.3:a:ays-pro:quiz_maker:*:*:*:*:*:wordpress:*:*

01 Apr 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-01 06:15

Updated : 2026-04-23 15:27


NVD link : CVE-2025-30774

Mitre link : CVE-2025-30774

CVE.ORG link : CVE-2025-30774


JSON object : View

Products Affected

ays-pro

  • quiz_maker
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')