Description
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions.
Published: 2026-09-30
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting (XSS)
Action: Patch Plugin
AI Analysis

Impact

An unauthenticated attacker can exploit the WordPress Quiz And Survey Master plugin to inject and execute arbitrary JavaScript within the site’s context, enabling cookie theft, session hijacking, defacement, or other malicious actions. The issue originates from insufficient sanitization of user input when creating quizzes and surveys, and the flaw is classified as CWE‑79. The impact includes loss of site confidentiality, integrity, and potential availability disruptions caused by malicious scripts.

Affected Systems

The vulnerability affects the ExpressTech Systems Quiz And Survey Master plugin for WordPress, versions 11.2.6 and earlier. All sites running an affected version are exposed; no other vendors or products are listed.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate‑to‑high risk. The EPSS score is not available and the flaw is not yet listed in CISA KEV, but the unauthenticated nature and wide usage of the plugin make exploitation likely. Attackers can target sites by navigating to quiz pages or by inserting malicious payloads into the plugin’s fields, which are rendered without proper sanitization. Prompt mitigation is therefore recommended.

Generated by OpenCVE AI on September 30, 2026 at 14:59 UTC.

Remediation

Vendor Solution

Update the WordPress Quiz And Survey Master plugin to the latest available version (at least 11.2.7).


OpenCVE Recommended Actions

  • Update the WordPress Quiz And Survey Master plugin to at least version 11.2.7.
  • If an immediate update is not possible, disable or remove the plugin’s quiz creation functionality for unauthenticated users or uninstall the plugin.
  • Apply a web application firewall rule or a Content Security Policy that blocks inline scripts injected by the plugin to mitigate XSS risk.

Generated by OpenCVE AI on September 30, 2026 at 14:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions.
Title WordPress Quiz And Survey Master plugin <= 11.2.6 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T13:37:19.393Z

Reserved: 2026-09-24T10:23:27.496Z

Link: CVE-2026-97289

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-30T13:17:39.210

Modified: 2026-09-30T14:18:18.027

Link: CVE-2026-97289

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T15:00:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')