Description
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order' parameter in all versions up to, and including, 11.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with admin-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. If the secret key is exposed, this can be exploited by lower-privileged users.
Published: 2026-06-05
Score: 4.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The QSM plugin for WordPress accepts a user supplied 'order' parameter that is not properly prepared or escaped, enabling a time‑based blind SQL injection attack. Authenticated users with admin or higher privileges can inject additional SELECT statements into existing database queries, allowing extraction of sensitive data. If a secret key used by the plugin is exposed, even lower‑privileged accounts may exploit the flaw. The vulnerability is a classic SQL injection described by CWE‑89.

Affected Systems

WordPress sites running the Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin, versions 11.1.2 and earlier. Administrators or accounts with higher privileges can trigger the injection through the plugin’s API.

Risk and Exploitability

The CVSS base score of 4.9 indicates a moderate risk, and the EPSS score is not available, so the current exploit probability is unknown. The flaw is not listed in CISA's KEV catalog. The requirement for authenticated access—usually an admin account—reduces the likelihood of a widespread attack, but the presence of an exposed secret key could lower the privilege threshold and increase exploitation risk.

Generated by OpenCVE AI on June 6, 2026 at 01:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the QSM plugin to a version newer than 11.1.2, which removes the vulnerable code.
  • Limit the number of users with admin or higher privileges and enforce strong, multi‑factor authentication for those accounts.
  • Regularly backup the WordPress database and monitor database query logs for suspicious activity that could indicate an attempted injection.

Generated by OpenCVE AI on June 6, 2026 at 01:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 06 Jun 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Expresstech
Expresstech quiz And Survey Master (qsm) – Easy Quiz And Survey Maker
Wordpress
Wordpress wordpress
Vendors & Products Expresstech
Expresstech quiz And Survey Master (qsm) – Easy Quiz And Survey Maker
Wordpress
Wordpress wordpress

Sat, 06 Jun 2026 00:00:00 +0000

Type Values Removed Values Added
Description The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order' parameter in all versions up to, and including, 11.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with admin-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. If the secret key is exposed, this can be exploited by lower-privileged users.
Title Quiz and Survey Master (QSM) <= 11.1.2 - Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Expresstech Quiz And Survey Master (qsm) – Easy Quiz And Survey Maker
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-06-05T23:28:27.562Z

Reserved: 2026-04-16T18:50:05.153Z

Link: CVE-2026-6448

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-06T00:16:41.477

Modified: 2026-06-06T00:16:41.477

Link: CVE-2026-6448

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-06T01:30:06Z

Weaknesses