Quiz Chaos: How Chained Quiz IDOR Puts Your Scores at Risk!
Chained Quiz 1.3.5 has a cookie vulnerability, making it easier to hijack quiz attempts like stealing candy from a baby. By tweaking the cookie value, an attacker can alter quiz responses without breaking a sweat or needing a login. It’s secure, said no one, ever.

Hot Take:
Who knew that a simple quiz could end up feeling more like a game of “Guess Who’s Submitting Your Quiz Answers?” The Chained Quiz plugin is turning ordinary quiz takers into unwitting quiz hackers. If only passing a test in school was this easy!
Key Points:
- Chained Quiz plugin has a vulnerability: Insecure Direct Object Reference (IDOR).
- Unauthenticated users can access and modify others’ quiz submissions.
- The vulnerability stems from predictable completion IDs stored in cookies.
- Attackers can manipulate quiz answers and scores without owning the data.
- This flaw poses a risk to any system reliant on quiz results for assessments or certifications.
Already a member? Log in here
