Impact
A SQL injection flaw has been identified in the Quiz And Survey Master WordPress plugin for versions up to 11.2.0; the vulnerability allows an attacker to inject malicious SQL via the plugin’s input fields, potentially enabling unauthorized database reads, updates, or deletions, which could expose or tamper with survey data, user credentials, or even compromise the hosting environment if the database account has elevated privileges. The weakness is classified as CWE‑89.
Affected Systems
The plugin is developed by ExpressTech Systems. Any installation of the Quiz And Survey Master WordPress plugin 11.2.0 or earlier is susceptible, all WordPress sites that have the vulnerable plugin enabled regardless of their WordPress version; the issue is remedied in version 11.2.1 and later.
Risk and Exploitability
The CVSS score of 8.5 denotes a high severity, while the EPSS score of less than 1% indicates a low probability of exploitation in the near term, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the likely attack vector is through any field offered by the plugin’s quiz or survey interfaces, which are accessible to site visitors, whether authenticated or not; an attacker who can successfully inject SQL may read, modify, or delete arbitrary data stored in the site’s database, and if the database user has broad permissions this might extend to the application layer.
OpenCVE Enrichment