What the vulnerability does
01Description
Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress.
Explanation of Vulnerability in Simple Terms
Quiz And Survey Master versions up to 7.3.6 contain an integrity issue that allows high-privileged users to modify data without proper authorization checks. The vulnerability requires administrator-level access and does not affect confidentiality or availability. Site owners should update to a version newer than 7.3.6 to remediate the issue.
What an attacker can do
Modify quiz or survey data through improper authorization checks.
Potential impact on your site
Administrators with malicious intent or compromised admin accounts can alter quiz/survey content without audit trail protection.
Conditions required to exploit
Attacker must have administrator-level access to the WordPress site.
Key dates
External resources