CVE-2022-41652 MEDIUM

CVE-2022-41652: WordPress Quiz And Survey Master plugin <= 7.3.10 - Bypass vulnerability

Vendor Expresstech
Product Quiz And Survey Master (WordPress plugin)
Published November 18, 2022
Last update April 28, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.

Explanation of Vulnerability in Simple Terms

02Summary

Quiz and Survey Master versions up to 7.3.10 contain a vulnerability that allows unauthenticated attackers to modify quiz and survey data or disrupt their availability. The vulnerability requires no user interaction and can be exploited over the network. Site administrators should update the plugin immediately to a version newer than 7.3.10.

What an attacker can do

03Attacker Capabilities

Modify quiz or survey content, or make quizzes and surveys unavailable without authentication.

Potential impact on your site

04Site Impact

Quiz and survey data could be altered or deleted by anyone on the internet, disrupting your assessments.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

November 18, 2022 CVE published
April 28, 2026 Record updated