Description
WordPress Plugin Quiz and Survey Master (QSM)-Easy Quiz and Survey Maker is prone to multiple vulnerabilities, including iFrame injection and input validation bypass vulnerabilities. Exploiting these issues could allow an attacker to inject iFrames in pages that will execute whenever a user accesses an injected page, or to send values other than the expected type. WordPress Plugin Quiz and Survey Master (QSM)-Easy Quiz and Survey Maker version 8.0.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 8.0.5 or latest
References
Related Vulnerabilities
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1975)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-4303)
Oracle Database Server CVE-2010-0852 Vulnerability (CVE-2010-0852)
WordPress Plugin Welcart e-Commerce PHP Object Injection (1.9.35)