CVE-2021-36865 LOW

CVE-2021-36865: WordPress Quiz And Survey Master plugin <= 7.3.4 - Insecure direct object references (IDOR) vulnerability

Vendor Expresstech
Product Quiz And Survey Master (WordPress plugin)
Published September 30, 2022
Last update April 28, 2026

CVSS base score

3.8/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz.

Explanation of Vulnerability in Simple Terms

02Summary

Quiz And Survey Master versions up to 7.3.4 contain a vulnerability that allows high-privileged users to modify site data. An administrator or editor can alter quiz or survey content and settings in ways that affect site integrity. The vulnerability requires administrative access and does not expose sensitive information. Update to a version newer than 7.3.4.

What an attacker can do

03Attacker Capabilities

Modify quiz or survey data and settings on the site.

Potential impact on your site

04Site Impact

Administrators or editors could maliciously alter quiz content, survey responses, or plugin settings without authorization.

Conditions required to exploit

05Prerequisites

Attacker must have high-level WordPress privileges (administrator or editor role).

Key dates

06Disclosure timeline

September 30, 2022 CVE published
April 28, 2026 Record updated