Impact
The vulnerability is a missing authorization flaw that allows attackers to bypass incorrectly configured access control security levels on ExpressTech Systems Quiz And Survey Master. This missing authorization (CWE‑862) gives potentially unauthorized users the ability to perform actions that should be restricted to authenticated or privileged users. The description does not specify the exact actions that become available, but the flaw permits bypassing typical access restrictions within the plugin.
Affected Systems
All installations of the ExpressTech Systems Quiz And Survey Master WordPress plugin up to and including version 10.3.3 are affected. The reference to n/a in the version range indicates that no earlier version is exempt; therefore any deployment of the plugin in these versions is vulnerable.
Risk and Exploitability
The CVSS score of 8.8 flags this issue as high severity, while the EPSS score of less than 1% shows a low probability of exploitation at present. It is not listed in the CISA KEV catalog. The attack vector is likely over the network through the plugin’s HTTP endpoints, as no local-only restrictions are mentioned. Therefore, the threat remains significant if no remediation is applied.
OpenCVE Enrichment