Quiz Maker Sensitive Information Exposure Vulnerability (CVE-2025-12426) — Medium Severity

Are you using the Quiz Maker plugin on your WordPress website? If so, there’s a critical security concern you need to be aware of. A recently discovered vulnerability, identified as CVE-2025-12426, could allow unauthorized individuals to access sensitive information, specifically the answers to your quizzes. This flaw has been rated with a Medium severity, making it important for site administrators and developers to take action promptly.

This vulnerability affects all versions of the Quiz Maker plugin up to and including 6.7.0.80. The issue stems from how the plugin handles quiz answer checks. It uses a special security token, known as a nonce, to verify actions. However, this nonce, which should ideally be private, is inadvertently made public to anyone visiting your site. This oversight allows attackers to bypass security checks and retrieve quiz answers without needing to be logged in or authorized. Essentially, it’s like leaving the answer key to a test out in the open for anyone to find.

CVE Details

This vulnerability is officially known as CVE-2025-12426.

  • Product: Quiz Maker plugin for WordPress
  • Published Date: November 19, 2025
  • Severity: Medium
  • Status: Analyzed

Affected Products

The Sensitive Information Exposure vulnerability impacts the Quiz Maker plugin for WordPress. Specifically, all versions up to, and including, 6.7.0.80 are at risk. If your WordPress site is running any of these versions, it is exposed to this security flaw.

Current Status

The vulnerability (CVE-2025-12426) has been thoroughly analyzed and publicly disclosed. This means the details of the flaw are now known, emphasizing the need for users to implement solutions to protect their sites.

Severity Level

This vulnerability carries a Medium severity rating with a CVSS score of 5.3. A Medium rating indicates that while the vulnerability is not the most severe, it still poses a significant risk. In this case, the risk is the unauthorized disclosure of sensitive information—your quiz answers. This could potentially lead to data integrity issues, unfair advantages in educational settings, or other unintended consequences depending on the nature of your quizzes.

Possible Solutions

The most effective way to address this vulnerability is to update your Quiz Maker plugin immediately. Users should update to a version beyond 6.7.0.80 as soon as a patched version is available from the plugin developer, AYS Pro. Always ensure you back up your website before performing any plugin updates. Regularly checking for and applying updates is a fundamental practice for maintaining a secure WordPress environment. For more information on general WordPress security, you might find our article Understanding WordPress Plugin Security helpful. To learn more about safeguarding user data, consider reading Best Practices for Protecting Sensitive Data.

References

https://plugins.trac.wordpress.org/browser/quiz-maker/tags/6.7.0.69/includes/class-quiz-maker.php#L393
https://plugins.trac.wordpress.org/browser/quiz-maker/tags/6.7.0.69/public/class-quiz-maker-public.php#L179
https://plugins.trac.wordpress.org/browser/quiz-maker/tags/6.7.0.69/public/class-quiz-maker-public.php#L8490
https://www.wordfence.com/threat-intel/vulnerabilities/id/bc524e3e-9b7c-47ae-ab44-c327b287b81a?source=cve

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.