Impact
The vulnerability is an insecure direct object reference that allows unauthenticated users to request arbitrary survey or quiz data by manipulating URLs or identifiers. This weak access control can lead to disclosure of other users’ responses or survey contents, but it does not provide code execution or higher‑level attacks. The weakness corresponds to CWE‑639. The CVSS score is 5.3, indicating moderate severity, while the EPSS score of < 1% shows a very low but nonzero chance of exploitation.
Affected Systems
ExpressTech Systems’ WordPress plugin Quiz And Survey Master, versions up to and including 11.2.5. Any site running these versions is vulnerable or later.
Risk and Exploitability
Risk analysis indicates a CVSS score of 5.3, reflecting moderate impact. The EPSS score of < 1% suggests an extremely low but nonzero probability of exploitation. The vulnerability is not in CISA’s KEV catalog. Because the flaw permits unauthenticated access to survey data, an attacker can read responses or survey structures without needing privileged credentials, but cannot execute code or modify site configuration. The web-based attack vector relies on manipulating URLs or identifiers within the plugin.
OpenCVE Enrichment