CVE-2024-5606: Quiz And Survey Master < 9.0.2 - Contributor+ SQLi
The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the questionid parameter in the qsmbulkdeletequestionfromdatabase AJAX action, leading to a SQL injection exploitable by Contributors and above role
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5606?
CVE-2024-5606 is considered a high-severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2024-5606?
To fix CVE-2024-5606, update the Quiz and Survey Master plugin to version 9.0.2 or later.
Who is affected by CVE-2024-5606?
CVE-2024-5606 affects WordPress users with Quiz and Survey Master plugin versions prior to 9.0.2.
What type of vulnerability is CVE-2024-5606?
CVE-2024-5606 is a SQL injection vulnerability that can be exploited via the question_id parameter.
What actions can exploit CVE-2024-5606?
Contributors and users with higher roles can exploit CVE-2024-5606 through the qsm_bulk_delete_question_from_database AJAX action.