Executive brief
ExpressTech Systems Quiz And Survey Master, a popular WordPress plugin used for creating interactive quizzes and surveys, contains a security vulnerability. An attacker with basic contributor-level access to the website could manipulate database queries to access sensitive information. This could lead to the unauthorized exposure of customer data or internal site configurations.
Technical details
A SQL injection vulnerability exists in the Quiz And Survey Master plugin for WordPress (versions <= 11.2.0) due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw allows an authenticated attacker with 'Contributor' or higher privileges to inject malicious SQL queries via the network. Successful exploitation could allow the attacker to read sensitive data from the database or cause minor availability issues. The vulnerability was addressed in version 11.2.1.
Affected products
- ExpressTech Systems Quiz And Survey Master <= 11.2.0
Timeline
- 2026-03-31: disclosed: Reported by anhcd05 to Patchstack
- 2026-07-22: advisory: Patchstack published advisory
- 2026-07-23: advisory: NVD published CVE record
- 2026-07-23: patched: Version 11.2.1 confirmed as patched version