CVE-2025-10302
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-03

Last updated on: 2025-10-06

Assigner: Wordfence

Description
The Ultimate Viral Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on thesave_options() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-03
Last Modified
2025-10-06
Generated
2026-05-07
AI Q&A
2025-10-03
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
wordpress ultimate_viral_quiz *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a Cross-Site Request Forgery (CSRF) issue in the Ultimate Viral Quiz plugin for WordPress, affecting all versions up to and including 1.0. It occurs because the plugin's save_options() function lacks proper nonce validation, allowing unauthenticated attackers to trick a site administrator into performing actions like updating plugin settings via a forged request.


How can this vulnerability impact me? :

The vulnerability allows an attacker to change the plugin's settings without authentication by tricking an administrator into clicking a malicious link. This can lead to unauthorized modification of plugin configurations, potentially disrupting site functionality or security.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, immediately update the Ultimate Viral Quiz plugin to a version later than 1.0 where the nonce validation issue is fixed. Additionally, avoid clicking on suspicious links and ensure that site administrators are aware of the risk of Cross-Site Request Forgery attacks. Implementing proper nonce validation in the plugin's save_options() function is necessary to prevent unauthorized settings changes.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart