CVE-2020-36504: Wp-Pro-Quiz Project Wp-Pro-Quiz
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
The WP-Pro-Quiz WordPress plugin through 0.37 does not have CSRF check in place when deleting a quiz, which could allow an attacker to make a logged in admin delete arbitrary quiz on the blog
Affected products
- Wp-Pro-Quiz Project Wp-Pro-Quiz: up to and including 0.37
Published 2021-11-01. Last modified 2026-06-17.