First published: Fri Oct 28 2022(Updated: )
Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Expresstech Quiz And Survey Master | <=7.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36864 is an Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress.
The severity of CVE-2021-36864 is medium with a CVSS score of 5.4.
CVE-2021-36864 affects the ExpressTech Quiz And Survey Master plugin version 7.3.4 and earlier.
To fix CVE-2021-36864, update the ExpressTech Quiz And Survey Master plugin to version 7.3.5 or later.
You can find more information about CVE-2021-36864 at the following links: - [Patchstack](https://patchstack.com/database/vulnerability/quiz-master-next/wordpress-quiz-and-survey-master-plugin-7-3-4-auth-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve) - [WordPress Plugin Directory](https://wordpress.org/plugins/quiz-master-next/#developers)