CVE-2025-9294: Quiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the qsmdashboarddeleteresult function in all versions up to, and including, 10.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete quiz results.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9294?
CVE-2025-9294 has been classified as a critical vulnerability due to potential unauthorized data loss.
How do I fix CVE-2025-9294?
To fix CVE-2025-9294, update the Quiz and Survey Master plugin to version 10.3.2 or later.
What versions of the Quiz and Survey Master plugin are affected by CVE-2025-9294?
CVE-2025-9294 affects all versions of the Quiz and Survey Master plugin up to and including version 10.3.1.
What type of vulnerability is CVE-2025-9294?
CVE-2025-9294 is a vulnerability that allows for unauthorized loss of data due to a missing capability check.
Who is at risk from CVE-2025-9294?
Users of the Quiz and Survey Master plugin on WordPress website versions up to 10.3.1 are at risk from CVE-2025-9294.