CVE-2025-9318: Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injection via the ‘islinking’ parameter in all versions up to, and including, 10.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9318?
CVE-2025-9318 is considered a high severity vulnerability due to its potential for a time-based SQL Injection attack.
How do I fix CVE-2025-9318?
To fix CVE-2025-9318, update the Quiz and Survey Master plugin to version 10.4 or later, which addresses the SQL Injection issue.
Which versions of the Quiz and Survey Master are affected by CVE-2025-9318?
CVE-2025-9318 affects all versions of the Quiz and Survey Master plugin up to and including version 10.3.1.
What type of vulnerability is CVE-2025-9318?
CVE-2025-9318 is a time-based SQL Injection vulnerability that occurs through insufficient escaping of user-supplied parameters.
Is CVE-2025-9318 exploitable by anonymous users?
Yes, CVE-2025-9318 can potentially be exploited by anonymous users because it involves a parameter that is accessible in the application.