CVE-2024-5606: Expresstech Quiz And Survey Master
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action, leading to a SQL injection exploitable by Contributors and above role
Affected products
- Expresstech Quiz And Survey Master: before 9.0.2 (fixed in 9.0.2)
Published 2024-07-02. Last modified 2026-06-17.