SQL Injection Vulnerability in Quiz and Survey Master WordPress Plugin by QSM
CVE-2024-5606

8.8HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
2 July 2024

Summary

The Quiz and Survey Master (QSM) WordPress plugin is susceptible to a SQL injection vulnerability due to insufficient validation and escaping of the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action. This weakness allows users with Contributor roles and above to exploit the vulnerability, potentially compromising the integrity of the database. Prior to version 9.0.2, the plugin does not effectively secure user input, making it critical for website administrators using this plugin to apply the necessary updates and enhance their security posture.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.