PricingCase studies Login Start trial
Plugin Icon

Quiz Maker

Ays Pro

Developer

6.7.1.22

Latest version

20,000

Installations

No date

Last updated

WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
    VulnerabilitiesSecurity Contributors

Vulnerability history

0 present
17 patched
8 Mitigation rules
  • Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
    <= 6.7.1.7
    19/02/2026
  • Cross Site Request Forgery (CSRF) vulnerability
    <= 6.7.1.2
    10/02/2026
  • Admin+ Stored XSS vulnerability
    < 6.7.0.89
    12/01/2026
  • Cross Site Request Forgery (CSRF) vulnerability
    <= 6.7.0.82
    02/12/2025
  • Unauthenticated Sensitive Information Exposure vulnerability
    <= 6.7.0.80
    18/11/2025
  • Cross Site Request Forgery (CSRF) Vulnerability
    <= 6.7.0.64
    22/09/2025
  • Sensitive Data Exposure Vulnerability
    <= 6.7.0.65
    22/09/2025
  • Unauthenticated SQL Injection vulnerability
    <= 6.7.0.56
    16/09/2025
  • Admin+ Stored XSS vulnerability
    <= 6.5.9.8
    19/05/2025
  • SQL Injection vulnerability
    <= 6.6.8.7
    29/03/2025
  • Unauthenticated SQL Injection via 'ays_questions' vulnerability
    <= 6.5.8.3
    25/06/2024
  • Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Creation & Modification vulnerability
    <= 6.5.2.4
    07/02/2024
  • Missing Authorization to Unauthenticated Quiz Data Retrieval vulnerability
    <= 6.5.2.4
    07/02/2024
  • Broken Access Control vulnerability
    <= 6.5.1.1
    05/01/2024
  • Reflected XSS vulnerability
    < 6.4.2.7
    22/06/2023
  • Content Spoofing
    <= 6.3.9.4
    20/01/2023
  • Multiple Authenticated Blind SQL Injection (SQLi) vulnerabilities
    <= 6.2.0.8
    29/06/2021

Vulnerability mitigation

  • Pricing
  • Application security (SCA)
  • RapidMitigate New
  • Threat Intelligence (API)
  • VS Monarx
  • VS Imunify360
  • VS Wordfence
  • Documentation
  • Service status
  • Log in

Code security

  • Managed VDP New
  • Active VDP directory 1,169
  • Security auditing
  • Compliance (CRA) New
  • Log in New

Bug bounty

  • Bug bounty
  • Leaderboard
  • Guidelines
  • Learn New
  • Report
  • Discord
  • Log in New

Use cases

  • Web developers
  • Webhosts New
  • Software vendors
  • WordPress
  • WooCommerce

Resources

  • Partners
  • Vulnerability database
  • Whitepaper 2026 New
  • Articles
  • Case studies New
  • Webinars New
  • Vulnerability statistics

Patchstack

  • About
  • Careers
  • Merch store
  • Media kit
  • LinkedIn
  • Facebook
  • X
© 2026 Patchstack
DPA
Privacy Policy
Accessibility
Terms & Conditions