Description
WordPress Plugin Thrive Quiz Builder is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently add arbitrary data to a predefined option in the wp_options table. WordPress Plugin Thrive Quiz Builder version 2.3.9.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.3.9.4 or latest
References
Related Vulnerabilities
WordPress Plugin WP jPlayer Cross-Site Scripting (0.1)
WordPress Plugin Social Share Icons & Social Share Buttons Security Bypass (3.0.2)
Joomla! Core 3.x.x Cross-Site Scripting (3.2.0 - 3.9.3)
Grafana Cleartext Storage of Sensitive Information Vulnerability (CVE-2020-12458)
TYPO3 Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2010-1153)