First published: Sun Jun 20 2021(Updated: )
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue. This could allow for privilege escalation by inducing a logged in admin to open a malicious link
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Expresstech Quiz And Survey Master | <7.1.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24368 refers to a vulnerability in the Quiz And Survey Master WordPress plugin that allows for reflected cross-site scripting (XSS) attacks.
CVE-2021-24368 affects the Quiz And Survey Master plugin by not properly sanitizing or escaping the result_id parameter, which can lead to a reflected XSS issue.
The severity of CVE-2021-24368 is medium, with a severity value of 6.1.
CVE-2021-24368 can be exploited by an attacker inducing a user to click on a maliciously crafted link containing the result_id parameter.
Yes, updating the Quiz And Survey Master plugin to version 7.1.18 or later will fix the vulnerability.