← back
CVE-2024-6879

Quiz and Survey Master (QSM) < 9.1.1 - Contributor+ Stored XSS

CVSS 4.7 MEDIUMEPSS 0.4%CWE-79
The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before displaying them on a page or post where the Quiz is embedded, which could allows contributor and above roles to perform Stored Cross-Site Scripting (XSS) attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →