Description
The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and including, 8.0.8. This makes it possible for unauthenticated attackers to delete arbitrary media files.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12368 | The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and including, 8.0.8. This makes it possible for unauthenticated attackers to delete arbitrary media files. |
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Quiz And Survey Master <= 8.0.8 - Unauthenticated Arbitrary Media Deletion | |
| Weaknesses | CWE-862 |
Sat, 28 Dec 2024 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:58:23.299Z
Reserved: 2023-01-13T16:54:28.658Z
Link: CVE-2023-0291
Updated: 2024-08-02T05:02:44.183Z
Status : Modified
Published: 2023-06-09T06:15:48.630
Modified: 2026-04-08T18:17:41.843
Link: CVE-2023-0291
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD