Impact
An unauthenticated attacker can exploit the WordPress Quiz And Survey Master plugin to inject and execute arbitrary JavaScript within the site’s context, enabling cookie theft, session hijacking, defacement, or other malicious actions. The issue originates from insufficient sanitization of user input when creating quizzes and surveys, and the flaw is classified as CWE‑79. The impact includes loss of site confidentiality, integrity, and potential availability disruptions caused by malicious scripts.
Affected Systems
The vulnerability affects the ExpressTech Systems Quiz And Survey Master plugin for WordPress, versions 11.2.6 and earlier. All sites running an affected version are exposed; no other vendors or products are listed.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‑to‑high risk. The EPSS score is not available and the flaw is not yet listed in CISA KEV, but the unauthenticated nature and wide usage of the plugin make exploitation likely. Attackers can target sites by navigating to quiz pages or by inserting malicious payloads into the plugin’s fields, which are rendered without proper sanitization. Prompt mitigation is therefore recommended.
OpenCVE Enrichment