Impact
An unauthenticated Cross Site Scripting flaw allows an attacker to inject malicious scripts through the Quiz And Survey Master plugin. The vulnerability is categorized as CWE-79 and can lead to session hijacking, cookie theft, defacement, or the execution of arbitrary code in the victim's browser. No authentication is required for exploitation, meaning any user accessing a vulnerable survey or quiz page could be affected.
Affected Systems
The vulnerability exists in ExpressTech’s Quiz And Survey Master WordPress plugin for all releases up to and including version 11.1.2. Any WordPress website that has this plugin installed and has not upgraded past 11.1.2 is impacted.
Risk and Exploitability
The CVSS score of 7.1 classifies this as a high severity flaw. The EPSS score of less than 1% indicates that, while the risk is high, the likelihood of active exploitation is currently low. The vulnerability is not listed in CISA’s KEV catalog, and the attack vector is inferred to be unauthenticated, typically through crafted input sent to the plugin’s public endpoints or embedded within quiz content.
OpenCVE Enrichment