PT-2026-47068 · WordPress · Quiz/Survey Master

·

CVE-2026-6448

·

Published

2026-06-05

·

Updated

2026-06-07

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker versions prior to 11.1.3
Description The plugin is susceptible to time-based blind SQL Injection, a technique where an attacker asks the database true/false questions and determines the answer based on the time the server takes to respond. This occurs due to insufficient escaping of user-supplied parameters and a lack of proper preparation of the SQL query. Authenticated attackers with admin-level access or higher can append additional SQL queries to extract sensitive information from the database via the order parameter. If the secret key is exposed, users with lower privileges may also be able to exploit this issue.
Recommendations Update the plugin to a version later than 11.1.2. As a temporary mitigation, restrict access to the order parameter to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6448

Affected Products

Quiz/Survey Master