Executive brief
The Quiz Master Next plugin for WordPress, used for creating quizzes and surveys, contains a security flaw that allows users with Author-level access to inject malicious database commands. By saving specially crafted quiz page data, an attacker can trick the system into revealing sensitive information from the website's database. This occurs when an administrator or another user views the affected quiz's settings, potentially leading to the exposure of private site data.
Technical details
The Quiz Master Next plugin for WordPress is vulnerable to a second-order SQL Injection due to insufficient input validation and output escaping. Specifically, the 'qsm_ajax_save_pages()' AJAX handler uses only 'sanitize_text_field()' on the 'pages' parameter, which is insufficient for preventing SQL injection when the data is later used in a query. The stored page IDs are subsequently interpolated into an IN() clause via 'implode()' in 'qsm_options_questions_tab_content()' without integer casting or the use of '$wpdb->prepare()'. Authenticated attackers with Author-level permissions can exploit this to plant a payload that executes when any user views the quiz's Questions tab, allowing for the extraction of sensitive database information.
Affected products
- ExpressTech Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker up to, and including, 11.2.0
Timeline
- 2026-07-16: disclosed: Initial publication of the CVE record.
- 2026-07-16: advisory: Wordfence published the vulnerability details.
References
- https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/11.2.0/php/admin/options-page-questions-tab.php
- https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/11.2.0/php/admin/options-page-questions-tab.php
- https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/11.2.0/php/classes/class-qmn-plugin-helper.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3608310%40quiz-master-next&new=3608310%40quiz-master-next
- https://www.wordfence.com/threat-intel/vulnerabilities/id/63fec549-09e0-4d4e-ae41-128ce0669501?source=cve