Are you using the Quiz Maker plugin on your WordPress website? If so, there’s a critical security concern you need to be aware of. A recently discovered vulnerability, identified as CVE-2025-12426, could allow unauthorized individuals to access sensitive information, specifically the answers to your quizzes. This flaw has been rated with a Medium severity, making it important for site administrators and developers to take action promptly.
This vulnerability affects all versions of the Quiz Maker plugin up to and including 6.7.0.80. The issue stems from how the plugin handles quiz answer checks. It uses a special security token, known as a nonce, to verify actions. However, this nonce, which should ideally be private, is inadvertently made public to anyone visiting your site. This oversight allows attackers to bypass security checks and retrieve quiz answers without needing to be logged in or authorized. Essentially, it’s like leaving the answer key to a test out in the open for anyone to find.
CVE Details
This vulnerability is officially known as CVE-2025-12426.
- Product: Quiz Maker plugin for WordPress
- Published Date: November 19, 2025
- Severity: Medium
- Status: Analyzed
Affected Products
The Sensitive Information Exposure vulnerability impacts the Quiz Maker plugin for WordPress. Specifically, all versions up to, and including, 6.7.0.80 are at risk. If your WordPress site is running any of these versions, it is exposed to this security flaw.
Current Status
The vulnerability (CVE-2025-12426) has been thoroughly analyzed and publicly disclosed. This means the details of the flaw are now known, emphasizing the need for users to implement solutions to protect their sites.
Severity Level
This vulnerability carries a Medium severity rating with a CVSS score of 5.3. A Medium rating indicates that while the vulnerability is not the most severe, it still poses a significant risk. In this case, the risk is the unauthorized disclosure of sensitive information—your quiz answers. This could potentially lead to data integrity issues, unfair advantages in educational settings, or other unintended consequences depending on the nature of your quizzes.
Possible Solutions
The most effective way to address this vulnerability is to update your Quiz Maker plugin immediately. Users should update to a version beyond 6.7.0.80 as soon as a patched version is available from the plugin developer, AYS Pro. Always ensure you back up your website before performing any plugin updates. Regularly checking for and applying updates is a fundamental practice for maintaining a secure WordPress environment. For more information on general WordPress security, you might find our article Understanding WordPress Plugin Security helpful. To learn more about safeguarding user data, consider reading Best Practices for Protecting Sensitive Data.
References
https://plugins.trac.wordpress.org/browser/quiz-maker/tags/6.7.0.69/includes/class-quiz-maker.php#L393
https://plugins.trac.wordpress.org/browser/quiz-maker/tags/6.7.0.69/public/class-quiz-maker-public.php#L179
https://plugins.trac.wordpress.org/browser/quiz-maker/tags/6.7.0.69/public/class-quiz-maker-public.php#L8490
https://www.wordfence.com/threat-intel/vulnerabilities/id/bc524e3e-9b7c-47ae-ab44-c327b287b81a?source=cve


