Vulnerability Description
The Quiz and Survey Master plugin for WordPress is vulnerable to input validation bypass via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input validation that allows attackers to inject content other than the specified value (i.e. a number, file path, etc..). This makes it possible attackers to submit values other than the intended input type.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Expresstech | Quiz And Survey Master | <= 8.0.4 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&oldPatchThird Party Advisory
- https://www.wordfence.com/threat-intel/vulnerabilities/id/9f5cc779-c7de-42e6-a81
- https://www.wordfence.com/vulnerability-advisories-continued/#CVE-2022-4033Third Party Advisory
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&oldPatchThird Party Advisory
- https://www.wordfence.com/vulnerability-advisories-continued/#CVE-2022-4033Third Party Advisory
FAQ
What is CVE-2022-4033?
CVE-2022-4033 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Quiz and Survey Master plugin for WordPress is vulnerable to input validation bypass via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input validation t...
How severe is CVE-2022-4033?
CVE-2022-4033 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-4033?
Check the references section above for vendor advisories and patch information. Affected products include: Expresstech Quiz And Survey Master.