Impact
The QSM plugin for WordPress accepts a user supplied 'order' parameter that is not properly prepared or escaped, enabling a time‑based blind SQL injection attack. Authenticated users with admin or higher privileges can inject additional SELECT statements into existing database queries, allowing extraction of sensitive data. If a secret key used by the plugin is exposed, even lower‑privileged accounts may exploit the flaw. The vulnerability is a classic SQL injection described by CWE‑89.
Affected Systems
WordPress sites running the Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin, versions 11.1.2 and earlier. Administrators or accounts with higher privileges can trigger the injection through the plugin’s API.
Risk and Exploitability
The CVSS base score of 4.9 indicates a moderate risk, and the EPSS score is not available, so the current exploit probability is unknown. The flaw is not listed in CISA's KEV catalog. The requirement for authenticated access—usually an admin account—reduces the likelihood of a widespread attack, but the presence of an exposed secret key could lower the privilege threshold and increase exploitation risk.
OpenCVE Enrichment