Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Watu Quiz — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Watu Quiz, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumeration (CWE) vulnerabilities associated with the Watu Quiz product developed by Watusi Software. It compiles security issues ranging from Cross-Site Scripting (XSS) to SQL injection and path traversal flaws found in various versions of the plugin. The collection covers advisory data and technical reports published between 2018 and 2023, reflecting the historical security posture of the software during this period. By reviewing this aggregated data, users can track specific vendor advisories and understand how different weakness classes have manifested in this particular environment. This resource allows administrators and security researchers to look up a product's vulnerability history, identifying patterns in exploitation and remediation timelines. Understanding these historical trends helps in assessing the overall risk profile of the application and evaluating the effectiveness of past security patches. The page serves as a centralized reference for analyzing how common coding errors have impacted this specific WordPress plugin over time, providing context for current security assessments without referencing individual CVE identifiers directly. This approach facilitates a broader understanding of the threat landscape surrounding Watu Quiz, enabling better decision-making regarding updates, alternative solutions, or defensive configurations based on comprehensive historical data rather than isolated incidents.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2025-68587 WordPress Watu Quiz plugin <= 3.4.5 - Broken Access Control vulnerability CWE-862 4.3 Medium 2025-12-24
CVE-2025-67976 WordPress Watu Quiz plugin <= 3.4.5 - Broken Access Control vulnerability CWE-862 6.5 Medium 2025-12-16
CVE-2025-11238 Watu Quiz <= 3.4.4 - Unauthenticated Stored Cross-Site Scripting via HTTP Referer CWE-79 7.2 High 2025-10-25
CVE-2025-46242 WordPress Watu Quiz plugin <= 3.4.3 - SQL Injection Vulnerability CWE-89 7.6 High 2025-04-22
CVE-2025-30844 WordPress Watu Quiz plugin <= 3.4.2 - Reflected Cross Site Scripting (XSS) Vulnerability CWE-79 7.1 High 2025-04-01
CVE-2024-53792 WordPress Watu Quiz plugin <= 3.4.1.2 - SQL Injection vulnerability CWE-89 8.5 High 2024-12-02
CVE-2024-2640 Watu Quiz < 3.4.1.2 - Author+ Stored XSS 4.8 - 2024-07-12
CVE-2024-0873 Watu Quiz <= 3.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-04-09
CVE-2024-0872 Watu Quiz <= 3.4.1 - Sensitive Information Disclosure CWE-639 4.3 Medium 2024-04-09
CVE-2023-30483 WordPress Watu Quiz Plugin <= 3.3.9.2 is vulnerable to Cross Site Scripting (XSS) CWE-79 7.1 High 2023-08-14
CVE-2023-25022 WordPress Watu Quiz Plugin <= 3.3.8 is vulnerable to Cross Site Scripting (XSS) CWE-79 5.9 Medium 2023-04-07
CVE-2023-0968 Watu Quiz <= 3.3.9 - Reflected Cross-Site Scripting CWE-79 6.1 Medium 2023-03-03
CVE-2023-0428 Watu Quiz < 3.3.8.2 - Reflected XSS 6.1 - 2023-02-21
CVE-2023-0429 Watu Quiz < 3.3.8.3 - Admin+ Stored XSS 4.8 - 2023-02-21

All 14 known CVE vulnerabilities affecting Watu Quiz with full Chinese analysis, references, and POCs where available.