Lucene search

K
wpvulndbWpvulndbWPVDB-ID:68E18A79-6C8D-4570-88E7-DD7A2256E6B8
HistoryNov 29, 2022 - 12:00 a.m.

Quiz and Survey Master < 8.0.5 - Unauthenticated iFrame Injection

2022-11-2900:00:00
wpscan.com
21
plugin vulnerability
unauthenticated users
iframe injection

EPSS

0.001

Percentile

28.7%

The plugin does not sanitise and escape the question[id] parameter, which could allow unauthenticated users to perform iFrame injection attack

EPSS

0.001

Percentile

28.7%

Related for WPVDB-ID:68E18A79-6C8D-4570-88E7-DD7A2256E6B8