CVE-2024-6025: Quiz and Survey Master < 9.0.5 - Contributor+ Stored XSS
Published Jul 11, 2024
·Updated
The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks
Affected Software
1 affected component
ExpressTech Quiz And Survey Master<9.0.5
Event History
Jul 11, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-6025?
CVE-2024-6025 has been classified with a high severity risk due to potential Stored Cross-Site Scripting attacks.
2
What does CVE-2024-6025 affect?
CVE-2024-6025 affects the Quiz and Survey Master plugin for WordPress versions prior to 9.0.5.
3
How do I fix CVE-2024-6025?
To fix CVE-2024-6025, update the Quiz and Survey Master plugin to version 9.0.5 or later.
4
Who can exploit CVE-2024-6025?
CVE-2024-6025 can be exploited by contributors and users with higher privileges on the WordPress site.
5
What kind of attack is possible with CVE-2024-6025?
CVE-2024-6025 allows the possibility of Stored Cross-Site Scripting attacks.