SQL Injection Vulnerability in Quiz and Survey Master WordPress Plugin by QSM
CVE-2024-5606
8.8HIGH
Summary
The Quiz and Survey Master (QSM) WordPress plugin is susceptible to a SQL injection vulnerability due to insufficient validation and escaping of the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action. This weakness allows users with Contributor roles and above to exploit the vulnerability, potentially compromising the integrity of the database. Prior to version 9.0.2, the plugin does not effectively secure user input, making it critical for website administrators using this plugin to apply the necessary updates and enhance their security posture.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published