SQL Injection Vulnerability in Quiz and Survey Master WordPress Plugin by QSM
CVE-2024-5606
8.8HIGH
What is CVE-2024-5606?
The Quiz and Survey Master (QSM) WordPress plugin is susceptible to a SQL injection vulnerability due to insufficient validation and escaping of the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action. This weakness allows users with Contributor roles and above to exploit the vulnerability, potentially compromising the integrity of the database. Prior to version 9.0.2, the plugin does not effectively secure user input, making it critical for website administrators using this plugin to apply the necessary updates and enhance their security posture.