CVE-2025-55708

8.5

ExpressTech Systems · Quiz And Survey Master

The Quiz And Survey Master WordPress plugin contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries.

Executive summary

A critical SQL injection vulnerability in the Quiz And Survey Master plugin allows authenticated attackers to potentially exfiltrate sensitive database information.

Vulnerability

This flaw is a CWE-89 SQL injection vulnerability triggered by improper neutralization of special elements in SQL commands, which can be exploited by any authenticated user with access to the plugin functions.

Business impact

The ability to perform SQL injection poses a significant risk to data confidentiality, as attackers may be able to read sensitive information directly from the underlying database. Given the CVSS score of 8.5, this high-severity vulnerability could lead to unauthorized data access and potential compromise of the application integrity, necessitating immediate attention to prevent exploitation.

Remediation

Immediate Action: Monitor the vendor for the release of an official security update and apply it immediately upon availability.

Proactive Monitoring: Review database query logs for suspicious patterns or anomalous input strings that deviate from standard plugin behavior.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block common SQL injection patterns and restrict access to plugin administrative functions to trusted personnel only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the potential for database compromise, organizations using the Quiz And Survey Master plugin must prioritize this issue. Administrators should ensure that the plugin is kept at the latest version or, if no patch is available, consider restricting access or deactivating the plugin until a secure version is released by ExpressTech Systems.

More ExpressTech Systems CVEs

Sources

Originally found and disclosed by Phat RiO | Patchstack Bug Bounty Program, per the CVE Program record.