Junglewise Threat Intelligence

CVE-2026-40787: ExpressTech Quiz And Survey Master unauthenticated XSS

CVE-2026-40787 · Severity: high · CVSS 7.1 · Published 2026-06-15

Technologies: ExpressTech Quiz and Survey Master. Vendors: ExpressTech.

Executive brief

Quiz And Survey Master is a popular WordPress plugin used to create and manage online quizzes and surveys. A security flaw allows unauthenticated attackers to inject malicious scripts into the website, which could lead to unauthorized redirects, theft of user session data, or the display of fraudulent content to site visitors. This risk is particularly high for sites that handle sensitive user feedback or require user logins.

Technical details

The Quiz And Survey Master plugin for WordPress is vulnerable to unauthenticated Cross-Site Scripting (XSS) due to improper neutralization of input during web page generation (CWE-79). This vulnerability exists in versions up to and including 11.0.0. An attacker can exploit this by sending a specially crafted request to the site, which requires a victim (such as an administrator or guest) to interact with a malicious link or page. Successful exploitation allows the execution of arbitrary JavaScript in the victim's browser session, which can be used to hijack sessions or modify page content. The issue is resolved in version 11.1.0.

Affected products

  • ExpressTech Quiz And Survey Master <= 11.0.0

Timeline

  • 2026-03-18: other: Reported by Jakub Herman
  • 2026-04-23: advisory: Initial advisory published by Patchstack
  • 2026-06-15: disclosed: CVE published to NVD

References

Related threats