Junglewise Threat Intelligence

CVE-2026-6448: WordPress Quiz and Survey Master SQL injection in order parameter

CVE-2026-6448 · Severity: medium · CVSS 4.9 · Published 2026-06-06

Technologies: ExpressTech Quiz and Survey Master. Vendors: ExpressTech.

Executive brief

The Quiz and Survey Master plugin for WordPress, which is used to create and manage online quizzes and surveys, contains a security flaw. An authorized user with administrative access could exploit this vulnerability to access sensitive information stored in the website's database. In certain configurations where a secret key is leaked, even lower-privileged users might be able to perform this attack, potentially leading to a broader data breach.

Technical details

A time-based blind SQL injection vulnerability exists in the 'order' parameter of the Quiz and Survey Master (QSM) plugin for WordPress. The issue stems from insufficient escaping of user-supplied input and a lack of proper SQL query preparation within the QSM Quiz API. Authenticated attackers with administrator-level privileges can exploit this to append arbitrary SQL queries and extract sensitive data from the database. If the plugin's secret key is compromised, the vulnerability may also be exploitable by users with lower privilege levels. The issue is present in all versions up to and including 11.1.2.

Affected products

  • ExpressTech Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker up to, and including, 11.1.2

Timeline

  • 2026-06-06: disclosed: Initial publication of the CVE record.

References

Related threats