PT-2021-11883 · WordPress · Quiz/Survey Master

Chloe Chamberland

·

Published

2021-01-01

·

Updated

2021-07-21

·

CVE-2020-35951

CVSS v3.1

9.9

Critical

VectorAC:L/AV:N/A:H/C:L/I:L/PR:N/S:C/UI:N
Name of the Vulnerable Software and Affected Versions: Quiz and Survey Master plugin versions prior to 7.0.1 for WordPress
Description: An issue in the Quiz and Survey Master plugin allows users to delete arbitrary files, such as the wp-config.php file, which could take a site offline and allow an attacker to reinstall with a WordPress instance under their control. This occurs via the qsm remove file fd question function, which allowed unauthenticated deletions, although it was intended only for deleting quiz-answer files.
Recommendations: For versions prior to 7.0.1, update to version 7.0.1 or later to resolve the issue. As a temporary workaround, consider disabling the qsm remove file fd question function until a patch is available. Restrict access to sensitive files, such as wp-config.php, to minimize the risk of exploitation.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-35951

Affected Products

Quiz/Survey Master