CVE-2025-6790: QSM < 10.2.3 - Template Creation via CSRF
Published Aug 14, 2025
·Updated
The Quiz and Survey Master (QSM) WordPress plugin before 10.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
Affected Software
1 affected component
Quiz and Survey Master QSM<10.2.3
Event History
Aug 14, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-6790?
CVE-2025-6790 has a medium severity rating due to its potential for CSRF attacks affecting admin settings.
2
How do I fix CVE-2025-6790?
To fix CVE-2025-6790, update the Quiz and Survey Master plugin to version 10.2.3 or later.
3
What type of attack does CVE-2025-6790 allow?
CVE-2025-6790 allows attackers to perform Cross-Site Request Forgery (CSRF) attacks on the plugin settings.
4
Who is affected by CVE-2025-6790?
Users of the Quiz and Survey Master WordPress plugin versions prior to 10.2.3 are affected by CVE-2025-6790.
5
What are the implications of CVE-2025-6790?
The implications of CVE-2025-6790 include unauthorized changes to admin settings, which can compromise website security.