CVE-2026-32342

WordPress Quiz Maker plugin <= 6.7.1.2 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Quiz Maker quiz-maker allows Cross Site Request Forgery.This issue affects Quiz Maker: from n/a through <= 6.7.1.2.


We have discovered 1,753 live websites that are affected by CVE-2026-32342.

Run a Free Instant Scan




Affected Software

Product  Quiz Maker
Category Wordpress Plugins
Vulnerable Domains1,753 live websites (37% of Quiz Maker install base)
Vulnerable Versions
  • from 0 through 6.7.1.2
Vulnerable Versions Count297 versions ( 79% of all versions)



Details

  • Published - Mar 13, 2026
  • Updated - Apr 1, 2026

Credits

  • w41bu1 | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-32342
United States430 websites



Germany185 websites
Russia125 websites
France86 websites
India74 websites
GB59 websites
Cyprus50 websites
Japan49 websites
Italy48 websites
Poland46 websites

Website Distribution by TLD

Number of websites using CVE-2026-32342
.com658 websites
.org118 websites
.ru96 websites
.de92 websites
.net49 websites
.it36 websites
.fr34 websites
.pl34 websites
.co.uk30 websites
.nl29 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-32342

Top websites that are affected by CVE-2026-32342. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.de Germany**,***
***********.com Austria**,***
****.ie United States**,***
*****************************.org United States***,***
*******.org United States***,***
***.***.br United States***,***
*****.***.my Malaysia***,***
***.al Albania***,***
**************.com India***,***
*********.hu Hungary***,***
See full domain list

FAQ

A total of 1,753 websites have been identified as vulnerable to CVE-2026-32342, based on global website indexing conducted by WebTechSurvey.
The Quiz Maker is affected by the CVE-2026-32342 vulnerability.
Quiz Maker versions up to and including 6.7.1.2 are vulnerable to CVE-2026-32342.