Quiz and Survey Master plugin vulnerable to Stored XSS attacks
CVE-2024-6879
Currently unrated
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 26 August 2024
Badges
πΎ Exploit Existsπ‘ Public PoC
Summary
The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before displaying them on a page or post where the Quiz is embedded, which could allows contributor and above roles to perform Stored Cross-Site Scripting (XSS) attacks.
Affected Version(s)
Quiz and Survey Master (QSM) 0 < 9.1.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Bereket Miheret
WPScan