Impact
Missing authorization in ExpressTech Systems Quiz And Survey Master (quiz-master-next) allows an attacker to bypass intended access control restrictions and perform actions with elevated privileges. The vulnerability can be leveraged to access or modify quiz and survey data, potentially exposing sensitive user information or manipulating content. It falls under CWE‑862, indicating a deficiency in proper permission enforcement.
Affected Systems
The flaw affects ExpressTech Systems Quiz And Survey Master plugin versions from the earliest releases through 10.3.4, including all intermediate releases. WordPress sites that have the plugin installed with a version equal to or lower than 10.3.4 are at risk. The plugin is distributed as part of WordPress, so any site using these versions is vulnerable.
Risk and Exploitability
The CVSS score is 4.3, representing a moderate severity. EPSS is below 1 %, indicating a low probability of exploitation at present, though no active exploitation has been reported. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the web interface; an adversary with web access can exploit the broken access control without requiring authentication. The issue does not require privileged credentials, making it accessible to publicly reachable attackers.
OpenCVE Enrichment