CVE-2025-55708
8.5ExpressTech Systems · Quiz And Survey Master
The Quiz And Survey Master WordPress plugin contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries.
Executive summary
A critical SQL injection vulnerability in the Quiz And Survey Master plugin allows authenticated attackers to potentially exfiltrate sensitive database information.
Vulnerability
This flaw is a CWE-89 SQL injection vulnerability triggered by improper neutralization of special elements in SQL commands, which can be exploited by any authenticated user with access to the plugin functions.
Business impact
The ability to perform SQL injection poses a significant risk to data confidentiality, as attackers may be able to read sensitive information directly from the underlying database. Given the CVSS score of 8.5, this high-severity vulnerability could lead to unauthorized data access and potential compromise of the application integrity, necessitating immediate attention to prevent exploitation.
Remediation
Immediate Action: Monitor the vendor for the release of an official security update and apply it immediately upon availability.
Proactive Monitoring: Review database query logs for suspicious patterns or anomalous input strings that deviate from standard plugin behavior.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block common SQL injection patterns and restrict access to plugin administrative functions to trusted personnel only.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the potential for database compromise, organizations using the Quiz And Survey Master plugin must prioritize this issue. Administrators should ensure that the plugin is kept at the latest version or, if no patch is available, consider restricting access or deactivating the plugin until a secure version is released by ExpressTech Systems.
More ExpressTech Systems CVEs
Sources
Originally found and disclosed by Phat RiO | Patchstack Bug Bounty Program, per the CVE Program record.