PT-2026-47068 · WordPress · Quiz/Survey Master
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker versions prior to 11.1.3
Description
The plugin is susceptible to time-based blind SQL Injection, a technique where an attacker asks the database true/false questions and determines the answer based on the time the server takes to respond. This occurs due to insufficient escaping of user-supplied parameters and a lack of proper preparation of the SQL query. Authenticated attackers with admin-level access or higher can append additional SQL queries to extract sensitive information from the database via the
order parameter. If the secret key is exposed, users with lower privileges may also be able to exploit this issue.Recommendations
Update the plugin to a version later than 11.1.2.
As a temporary mitigation, restrict access to the
order parameter to minimize the risk of exploitation.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quiz/Survey Master