Impact
A SQL Injection flaw exists in the Quiz and Survey Master (QSM) WordPress plugin, allowing an authenticated user with Contributor or higher privileges to include arbitrary SQL statements through the "randon_category" option. The insufficient data sanitisation and inappropriate query construction give the attacker the ability to read or potentially modify database contents, exposing sensitive user information or site data. Failing to address this could result in an untrusted party accessing or exfiltrating confidential information stored in the WordPress database.
Affected Systems
The vulnerability affects all installations of the expresstech QSM plugin up to and including version 11.2.1. Any WordPress site using this plugin with user roles of Contributor or higher is susceptible, regardless of other configuration settings.
Risk and Exploitability
The CVSS score of 6.5 classifies this as a medium severity threat, and while no EPSS value is available, the exploitation potential remains significant because the attacker only needs valid authentication. The flaw is not listed in CISA’s KEV catalog, but its presence in a widely used plugin suggests it could be leveraged by threat actors. The likely attack vector is via normal site activity where the compromised contributor edits or creates a quiz, leveraging the injection point to extract data.
OpenCVE Enrichment