CVE-2016-11085: XSS
php/qmnoptionsquestionstab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant stored XSS, via the questionname parameter because js/adminquestion.js mishandles parsing inside of a SCRIPT element.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2016-11085.
What is the title of this vulnerability?
The title of this vulnerability is 'php/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant stored XSS, via the question_name parameter because js/admin_question.js mishandles parsing inside of a SCRIPT element.'
What is the severity of CVE-2016-11085?
The severity of CVE-2016-11085 is medium with a CVSS score of 6.5.
Which software is affected by CVE-2016-11085?
The Expresstech Quiz And Survey Master plugin before version 4.7.9 for WordPress is affected by CVE-2016-11085.
Is there a fix available for CVE-2016-11085?
Yes, updating the plugin to version 4.7.9 or newer will fix CVE-2016-11085.