Sceawere

Vulnerability Detail

CVE-2026-94082UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Quiz Cat SQL Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.6
Creation Date
3h ago
Vendor
Fatcatapps
Product
Quiz Cat
Attack Type
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Author SQL Injection in Quiz Cat <= 3.1.1 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.6",
  "pubDate": "2026-09-30T13:17:24.093Z",
  "pubdate": "2026-09-30T13:17:24.093Z",
  "executiveSummary": "The Quiz Cat plugin for WordPress, specifically versions 3.1.1 and earlier, is susceptible to an authenticated SQL injection vulnerability.\nThis flaw allows a malicious actor with specific administrative or author-level privileges to execute arbitrary SQL queries against the underlying database.\nThe vulnerability arises from improper neutralization of user-supplied data before incorporating it into database queries.\nAn attacker can leverage this weakness to manipulate backend data, potentially leading to unauthorized data exfiltration, modification, or bypass of security controls within the WordPress environment.\nThe impact is significant, as successful exploitation grants the attacker direct access to the database layer, which may contain sensitive user information, configurations, or credentials.\nThis risk is particularly relevant for WordPress installations where multiple users have author-level access, as the vulnerability requires authentication to trigger the flawed request.\nThe scope of exploitation is limited to the database interaction layer but can result in full compromise of site data if utilized to extract administrative credentials or inject malicious records.",
  "technicalDetails": "The vulnerability originates from the improper sanitization and validation of input parameters within the Quiz Cat plugin's processing logic, specifically affecting functions that interact directly with the WordPress database via the $wpdb class.\nIn versions 3.1.1 and below, user-controlled input transmitted via HTTP requests is concatenated into SQL statements without the use of proper prepared statements or adequate escaping functions like $wpdb->prepare().\nAn authenticated attacker can inject malicious SQL syntax into the vulnerable parameters, effectively altering the structure of the intended query. By manipulating these queries, an attacker can perform UNION-based SQL injection to append results from other tables, or blind-based injection to infer database content through time-based or boolean-based response variances.\nThe attack flow typically involves an authenticated user crafting an HTTP request containing a crafted payload. When the application processes this request, the backend SQL engine executes the injected commands as part of the database transaction.\nBecause the application fails to distinguish between data and SQL instructions, the injected code is interpreted by the database management system (DBMS).\nPost-exploitation impact ranges from unauthorized information disclosure—where attackers can extract user hashes, site settings, or sensitive plugin configuration—to potentially modifying records within the wp_posts or custom plugin tables.\nIn some scenarios, if the database user has elevated permissions, the vulnerability might be leveraged to perform file operations or interact with system-level tables, though this is dependent on the specific hosting environment's database configuration.\nThe vulnerability is limited to the authenticated context, meaning an attacker must possess valid credentials for an account with the capability to trigger the vulnerable functions. Once inside the application, the lack of server-side input validation allows the attacker to bypass standard application-level access controls to probe the database directly."
}
CVE-2026-94082: Quiz Cat SQL Injection Vulnerability (HIGH Severity, CVSS: 7.6) | Sceawere