Impact
The vulnerability is a stored cross‑site scripting flaw that arises from inadequate sanitization and escaping of the 'question_title' field in the Quiz and Survey Master plugin for WordPress. Authenticated users with contributor or higher privileges can insert malicious scripts into a question title, and those scripts are rendered when any visitor views the question page. This allows an attacker to execute arbitrary code in the victim’s browser, potentially enabling session hijacking, defacement, or the execution of further malicious actions within the site context.
Affected Systems
The affected product is the Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker WordPress plugin, developed by expresstech, in all releases up to and including version 11.2.1. Any WordPress site that has this plugin installed and is running a vulnerable version is susceptible.
Risk and Exploitability
The CVSS score is 6.4, indicating a moderate severity level. The EPSS score is not available, so the current likelihood of exploitation in the wild is unclear. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires authenticated access with contributor‑level rights or higher, and the attacker must submit a malicious question title via the admin interface or the exposed REST API. Once stored, the payload executes whenever a user navigates to the affected question, providing a typical client‑side attack surface.
OpenCVE Enrichment