Impact
This vulnerability allows users with contributor-level access and higher to delete any template output files of the Quiz and Survey Master WordPress plugin. The deletion removes stored form configurations and surveys, potentially disrupting user data and site functionality. The weakness, identified as CWE‑862, represents an improper authorization check. The impact is limited to loss of configuration data and possible interruption of service, rather than direct code execution or data exfiltration.
Affected Systems
Quiz and Survey Master plugin versions earlier than 11.1.5 on any WordPress installation are affected. The issue is present in all builds before the 11.1.5 release, regardless of other WordPress components. Users who rely on QSM to host quizzes or surveys should verify the plugin version and update if necessary.
Risk and Exploitability
The CVSS score of 2.7 indicates low severity, and the EPSS score of less than 1% shows exploitation is unlikely. It is not listed in the CISA KEV catalog. The attack requires an authenticated user with contributor-level permissions; thus, it is an authenticated, local administrative attack. The vulnerability can be exploited by any user who can access the WordPress dashboard and is granted contributor capabilities, allowing them to delete templates without additional prerequisites.
OpenCVE Enrichment