Junglewise Threat Intelligence

CVE-2026-48867: ExpressTech Quiz And Survey Master unauthenticated XSS

CVE-2026-48867 · Severity: high · CVSS 7.1 · Published 2026-06-15

Technologies: ExpressTech Quiz and Survey Master. Vendors: ExpressTech.

Executive brief

The Quiz And Survey Master plugin for WordPress, which is used to create interactive quizzes and surveys, contains a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor clicks a specially crafted link, the attacker could potentially hijack user sessions, redirect visitors to malicious sites, or deface the website. This vulnerability can be exploited by remote attackers without needing any login credentials.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in the Quiz And Survey Master plugin for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to execute arbitrary JavaScript in the context of a user's browser session. Exploitation requires a victim to interact with a malicious link or crafted page (User Interaction: Required). Successful exploitation can lead to session hijacking, unauthorized actions on behalf of the user, or delivery of further browser-based exploits. The issue is resolved in version 11.1.3.

Affected products

  • ExpressTech Quiz And Survey Master <= 11.1.2

Timeline

  • 2026-04-25: other: Reported by researcher endy
  • 2026-06-03: advisory: Initial disclosure by Patchstack
  • 2026-06-15: disclosed: NVD publication date
  • 2026-06-03: patched: Version 11.1.3 released

References

Related threats