CVE-2020-7104: Kibokolabs Chained Quiz

Medium severity, CVSS 6.1. EPSS: 1.6% chance of exploitation in the next 30 days.

The chained-quiz plugin 1.1.8.1 for WordPress has reflected XSS via the wp-admin/admin-ajax.php total_questions parameter.

Affected products

Published 2020-01-17. Last modified 2026-06-17.