CVE-2024-8758: Quiz and Survey Master (QSM) < 9.1.3 - Author+ Stored XSS
The Quiz and Survey Master (QSM) WordPress plugin before 9.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8758?
CVE-2024-8758 is classified as a medium severity vulnerability due to its potential for allowing Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-8758?
To fix CVE-2024-8758, update the Quiz and Survey Master plugin to version 9.1.3 or later.
Who is affected by CVE-2024-8758?
Administrators and users with high privileges in WordPress using versions of the Quiz and Survey Master plugin prior to 9.1.3 are affected by CVE-2024-8758.
What type of vulnerability is CVE-2024-8758?
CVE-2024-8758 is a Stored Cross-Site Scripting (XSS) vulnerability.
When was CVE-2024-8758 disclosed?
CVE-2024-8758 was disclosed in 2024 alongside the release of the fixed version of the Quiz and Survey Master plugin.