Impact
The vulnerability allows a contributor or higher to modify the front‑end text settings of quizzes that were created by other users because the plugin does not verify the owner of the quiz before saving the settings. This flaw could enable an attacker to change quiz content or display, potentially misleading respondents or defacing a quiz.\n
Affected Systems
This flaw affects the Quiz and Survey Master WordPress plugin prior to version 11.2.4. Any installation running a version earlier than 11.2.4 is potentially vulnerable; there is no official back‑port or patch beyond that version.\n
Risk and Exploitability
The CVSS score of 2.7 indicates low overall impact. The EPSS score of less than 1% suggests that exploitation in the wild is very unlikely, and the flaw is not listed in the CISA KEV catalog. Attackers would need contributor or higher WordPress roles and can exploit the issue through the front‑end editing interface, but the damage is limited to tampering with quiz text content.
OpenCVE Enrichment