CVE-2024-4934: Quiz And Survey Master < 9.0.2 - Contributor+ Stored XSS
The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in a page/post where the Quiz is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4934?
CVE-2024-4934 is rated as a medium severity vulnerability due to its potential for allowing Stored Cross-Site Scripting.
How do I fix CVE-2024-4934?
To fix CVE-2024-4934, update the Quiz and Survey Master plugin to version 9.0.2 or later.
Who is affected by CVE-2024-4934?
CVE-2024-4934 affects users with the contributor role and above on WordPress sites using the vulnerable plugin.
What kind of attack can be executed through CVE-2024-4934?
CVE-2024-4934 allows for Stored Cross-Site Scripting attacks, which can compromise user accounts.
Is CVE-2024-4934 specific to certain versions of the plugin?
Yes, CVE-2024-4934 affects versions of the Quiz and Survey Master plugin before 9.0.2.