Vulnerability Description
The Quiz And Survey Master WordPress plugin before 8.1.11 does not properly sanitize and escape question titles, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Expresstech | Quiz And Survey Master | < 8.1.11 |
References
- https://wpscan.com/vulnerability/6f884688-2c0d-4844-bd31-ef7085edf112ExploitThird Party Advisory
- https://www.onvio.nl/nieuws/research-day-discovering-vulnerabilities-in-wordpresExploit
- https://wpscan.com/vulnerability/6f884688-2c0d-4844-bd31-ef7085edf112ExploitThird Party Advisory
- https://www.onvio.nl/nieuws/research-day-discovering-vulnerabilities-in-wordpresExploit
FAQ
What is CVE-2023-3575?
CVE-2023-3575 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The Quiz And Survey Master WordPress plugin before 8.1.11 does not properly sanitize and escape question titles, which could allow users with the Contributor role and above to perform Stored Cross-Sit...
How severe is CVE-2023-3575?
CVE-2023-3575 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-3575?
Check the references section above for vendor advisories and patch information. Affected products include: Expresstech Quiz And Survey Master.