VYPR
Medium severity4.3NVD Advisory· Published Jan 23, 2026· Updated Apr 15, 2026

CVE-2026-24544

CVE-2026-24544

Description

Missing Authorization vulnerability in Harmonic Design HD Quiz hd-quiz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HD Quiz: from n/a through <= 2.0.9.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in HD Quiz plugin (≤2.0.9) allows unprivileged users to exploit incorrectly configured access controls.

Vulnerability

Overview

The HD Quiz plugin for WordPress, versions 2.0.9 and earlier, contains a missing authorization vulnerability. This is a broken access control issue where the plugin fails to properly verify user permissions before allowing certain actions. The flaw stems from missing authorization checks, nonce token validation, or authentication requirements in one or more functions, enabling unprivileged users to execute actions that should require higher privileges [1].

Exploitation

An attacker can exploit this vulnerability without needing any special privileges or authentication. The attack vector is network-based, with low attack complexity. No user interaction is required, and the vulnerability can be triggered remotely. This type of vulnerability is commonly used in mass-exploit campaigns targeting thousands of websites simultaneously, regardless of site traffic or popularity [1].

Impact

Successful exploitation allows an attacker to perform actions that should be restricted to higher-privileged users. The CVSS v3 base score is 4.3 (Medium), indicating a moderate severity. The impact is limited to low-level access control bypass, but when combined with other vulnerabilities or in automated attacks, it can lead to broader compromise [1].

Mitigation

The vulnerability has been addressed in version 2.0.10 of the HD Quiz plugin. Users are strongly advised to update immediately. For Patchstack users, auto-updates for vulnerable plugins can be enabled. If updating is not possible, contacting the hosting provider or web developer for assistance is recommended [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.