What the vulnerability does
01Description
Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz.
Explanation of Vulnerability in Simple Terms
Quiz And Survey Master versions up to 7.3.4 contain a vulnerability that allows high-privileged users to modify site data. An administrator or editor can alter quiz or survey content and settings in ways that affect site integrity. The vulnerability requires administrative access and does not expose sensitive information. Update to a version newer than 7.3.4.
What an attacker can do
Modify quiz or survey data and settings on the site.
Potential impact on your site
Administrators or editors could maliciously alter quiz content, survey responses, or plugin settings without authorization.
Conditions required to exploit
Attacker must have high-level WordPress privileges (administrator or editor role).
Key dates
External resources