{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/quiz-maker--6.5.8.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ays-pro:quiz_maker:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2024-6028"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Quiz Maker (\u003c= 6.5.8.3)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["Ays-pro"],"content_html":"\u003cp\u003eCVE-2024-6028 is a high-severity time-based SQL injection vulnerability affecting the Ays-pro Quiz Maker WordPress plugin, versions 6.5.8.3 and lower. The vulnerability resides within the 'ays_questions' parameter processed by the 'ays_finish_quiz' action in the 'Quiz_Maker_Public' class. An unauthenticated attacker can exploit this flaw by sending a specially crafted HTTP POST request to the WordPress 'admin-ajax.php' endpoint. Due to the lack of sufficient input sanitization and parameter escaping, the attacker can inject malicious SQL commands that the application executes against the underlying WordPress database. Successful exploitation allows an attacker to infer sensitive information through time-based inferencing (e.g., using the MySQL SLEEP function). The vulnerability has a CVSS 9.8 rating, and a publicly available proof-of-concept exploit increases the risk of immediate exploitation by malicious actors.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated attackers to gain unauthorized access to the application database. This can result in the full compromise of sensitive data stored within the WordPress environment, including user accounts, site configurations, and potentially other plugins' data. Given the widespread use of WordPress plugins, this vulnerability presents a significant risk to the confidentiality and integrity of affected sites.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Ays-pro Quiz Maker plugin to version 6.5.8.4 or later immediately.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to monitor for suspicious POST requests targeting 'admin-ajax.php' containing SQL injection syntax in the 'ays_questions' parameter.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous spikes in response times coupled with POST requests to 'admin-ajax.php', which may indicate active time-based SQL injection attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T01:09:10Z","date_published":"2026-09-01T01:09:10Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2024-6028-quiz-maker-sqli/","summary":"An unauthenticated time-based SQL injection vulnerability (CVE-2024-6028) exists in Ays-pro Quiz Maker plugin versions 6.5.8.3 and earlier, allowing attackers to exfiltrate database content via crafted POST requests.","title":"Critical SQL Injection in Quiz Maker WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2024-6028-quiz-maker-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Quiz Maker (\u003c= 6.5.8.3)","version":"https://jsonfeed.org/version/1.1"}