Executive brief
Netro Systems Make My Trivia, a WordPress plugin used for creating trivia content, contains a security flaw in its access control settings. An unauthorized user could potentially bypass security restrictions to access or modify information that should be protected. This could lead to unauthorized changes to trivia content or exposure of internal plugin data.
Technical details
The Make My Trivia (trivialy) plugin for WordPress, up to and including version 1.1.0, suffers from a missing authorization vulnerability (CWE-862). The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before allowing access to certain functions. An unauthenticated remote attacker can exploit this by sending crafted network requests to the affected site. Depending on the specific endpoint reached, this could allow for unauthorized data retrieval or modification of plugin settings. As of the advisory date, no official patch has been released.
Affected products
- Netro Systems Make My Trivia (trivialy) <= 1.1.0
Timeline
- 2026-01-30: other: Vulnerability reported by researcher Nabil Irawan
- 2026-03-01: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published to NVD