Quiz Maker Plugin Time-Based SQL Injection Vulnerability (CVE-2024-6028) — Critical Severity

The Quiz Maker plugin for WordPress has a severe security flaw that could put your website’s data at risk. This critical vulnerability, identified as CVE-2024-6028, is a time-based SQL Injection that allows unauthorized individuals to potentially steal sensitive information from your site’s database.

### CVE Details
The vulnerability affects the **Quiz Maker plugin for WordPress**. It was publicly disclosed on **June 25, 2024**, and has been classified with a **Critical** severity level. The status of this vulnerability is currently **Analyzed**.

### Affected Products
This security issue impacts all versions of the Quiz Maker plugin for WordPress up to, and including, **6.5.8.3**. If you are running any version within this range, your website is susceptible to this vulnerability. The flaw exists because the plugin did not properly handle user input in the ‘ays_questions’ parameter, making it easy for attackers to insert malicious code into database queries.

### Current Status
The vulnerability has been thoroughly analyzed, and its details are now widely known within the cybersecurity community. This means that potential attackers are likely aware of it and may be actively looking for vulnerable WordPress sites.

### Severity Level
With a CVSS score of 9.8, this vulnerability is rated as **Critical**. This is the highest possible severity rating, indicating a significant risk. A time-based SQL Injection allows an unauthenticated attacker—meaning someone without any login credentials—to execute malicious database queries. This could lead to the extraction of sensitive data such as user information, passwords (if not properly hashed), and other confidential records stored in your WordPress database. The “time-based” aspect means attackers can deduce information character by character, observing delays in database responses, even if direct error messages are suppressed.

### Possible Solutions
The most important step you can take to protect your WordPress site is to **update the Quiz Maker plugin immediately**. The vulnerability has been addressed in version **6.5.8.4 and later**.

To update your plugin:
1. Log in to your WordPress admin dashboard.
2. Navigate to ‘Plugins’ -> ‘Installed Plugins’.
3. Locate the ‘Quiz Maker’ plugin.
4. If an update to version 6.5.8.4 or higher is available, click ‘Update Now’.
5. Always back up your website before performing any updates.

Beyond applying this specific patch, it’s always good practice to:
* Regularly update all your WordPress themes and plugins.
* Use a strong, unique password for your WordPress admin account and other user accounts.
* Employ a reputable security plugin (like Wordfence, mentioned in the references) to monitor your site for suspicious activity and provide an additional layer of defense.
* Implement a Web Application Firewall (WAF) to filter out malicious traffic before it reaches your server.

### References
https://plugins.trac.wordpress.org/browser/quiz-maker/tags/6.5.7.5/public/class-quiz-maker-public.php#L4904
https://plugins.trac.wordpress.org/browser/quiz-maker/tags/6.5.7.5/public/class-quiz-maker-public.php#L6901
https://plugins.trac.wordpress.org/changeset/3103402/quiz-maker/tags/6.5.8.2/public/class-quiz-maker-public.php?old=3102679&old_path=quiz-maker%2Ftags%2F6.5.8.1%2Fpublic%2Fclass-quiz-maker-public.php
https://plugins.trac.wordpress.org/changeset/3105555/quiz-maker/tags/6.5.8.4/public/class-quiz-maker-public.php?old=3104323&old_path=quiz-maker%2Ftags%2F6.5.8.3%2Fpublic%2Fclass-quiz-maker-public.php

Quiz Maker


https://www.wordfence.com/threat-intel/vulnerabilities/id/ab340c65-35eb-4a85-8150-3119b46c7f35?source=cve
https://plugins.trac.wordpress.org/browser/quiz-maker/tags/6.5.7.5/public/class-quiz-maker-public.php#L4904
https://plugins.trac.wordpress.org/browser/quiz-maker/tags/6.5.7.5/public/class-quiz-maker-public.php#L6901
https://plugins.trac.wordpress.org/changeset/3103402/quiz-maker/tags/6.5.8.2/public/class-quiz-maker-public.php?old=3102679&old_path=quiz-maker%2Ftags%2F6.5.8.1%2Fpublic%2Fclass-quiz-maker-public.php
https://plugins.trac.wordpress.org/changeset/3105555/quiz-maker/tags/6.5.8.4/public/class-quiz-maker-public.php?old=3104323&old_path=quiz-maker%2Ftags%2F6.5.8.3%2Fpublic%2Fclass-quiz-maker-public.php

Quiz Maker


https://www.wordfence.com/threat-intel/vulnerabilities/id/ab340c65-35eb-4a85-8150-3119b46c7f35?source=cve

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.