CVE-2024-6879: Quiz and Survey Master (QSM) < 9.1.1 - Contributor+ Stored XSS
The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before displaying them on a page or post where the Quiz is embedded, which could allows contributor and above roles to perform Stored Cross-Site Scripting (XSS) attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6879?
CVE-2024-6879 is categorized as a medium severity vulnerability due to the potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2024-6879?
To fix CVE-2024-6879, update the Quiz and Survey Master plugin to version 9.1.1 or later.
Who is affected by CVE-2024-6879?
Users with contributor or higher permissions on WordPress sites using vulnerable versions of the Quiz and Survey Master plugin are affected.
What kind of attack can be performed using CVE-2024-6879?
CVE-2024-6879 allows an attacker to perform stored cross-site scripting (XSS) attacks by exploiting unvalidated quiz fields.
What versions of the Quiz and Survey Master plugin are vulnerable to CVE-2024-6879?
Versions of the Quiz and Survey Master plugin prior to 9.1.1 are vulnerable to CVE-2024-6879.