CVE-2026-65454
ExpressTech · Quiz And Survey Master
The Quiz And Survey Master plugin for WordPress is susceptible to an SQL injection vulnerability, enabling authenticated contributors to perform unauthorized database operations.
Executive summary
A high severity SQL injection vulnerability in the Quiz And Survey Master plugin allows authenticated contributors to compromise database security.
Vulnerability
This is a SQL injection vulnerability resulting from improper input sanitization. The issue is accessible to users with contributor-level privileges or higher.
Business impact
Exploitation of this vulnerability enables attackers to bypass intended database access restrictions, risking the exposure of sensitive user or survey data. The CVSS score of 8.5 reflects the high potential for impact on data integrity and confidentiality.
Remediation
Immediate Action: Update the Quiz And Survey Master plugin to version 11.2.1 or later as the primary mitigation step.
Proactive Monitoring: Monitor database query performance and logs for suspicious SQL syntax or signs of unauthorized table access.
Compensating Controls: Utilize a Web Application Firewall to filter and sanitize incoming requests for potential SQL injection strings.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Security teams should treat this vulnerability with high urgency. Applying the vendor-provided update is necessary to prevent potential data breaches facilitated by this SQL injection flaw.