WordPress Plugin Vulnerabilities

Quiz and Survey Master (QSM) < 9.1.1 - Contributor+ Stored XSS

Description

The plugin fails to validate and escape certain Quiz fields before displaying them on a page or post where the Quiz is embedded, which could allows contributor and above roles to perform Stored Cross-Site Scripting (XSS) attacks.

Proof of Concept

Affects Plugins

Fixed in 9.1.1

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Bereket Miheret
Submitter
Bereket Miheret
Verified
Yes

Timeline

Publicly Published
2024-08-05 (about 1 year ago)
Added
2024-08-05 (about 1 year ago)
Last Updated
2024-08-05 (about 1 year ago)

Other