Impact
A flaw in the Quiz and Survey Master WordPress plugin allows an insecure direct object reference in the REST API to expose email‑notification and results‑page configuration data for quizzes. The exposed data includes recipient addresses that could be harvested for phishing or spam. The vulnerability does not grant code execution or privilege escalation, but it leaks sensitive configuration information to users beyond the quiz owner.
Affected Systems
Any WordPress installation running Quiz and Survey Master version earlier than 11.2.4 is vulnerable. Contributors or higher users can utilize the exposed REST routes to read other users' quiz configuration settings.
Risk and Exploitability
The CVSS score of 2.7 indicates low severity, and the EPSS score of less than 1 % suggests a low likelihood of exploitation today. The vulnerability is not listed in the CISA KEV catalog. While exploitation is unlikely, the leaked configuration data could be used in future phishing or spam campaigns, so remediation is recommended.
OpenCVE Enrichment