Lucene search

K
wpvulndbWpvulndbWPVDB-ID:8CAFF9DF-9365-4511-98A6-714C4F67BFDD
HistoryOct 21, 2022 - 12:00 a.m.

Quiz And Survey Master < 7.3.11 - Subscriber+ XSS

2022-10-2100:00:00
wpscan.com
8
cross-site scripting
subscriber role
vulnerability

EPSS

0.001

Percentile

31.3%

The plugin does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks

EPSS

0.001

Percentile

31.3%

Related for WPVDB-ID:8CAFF9DF-9365-4511-98A6-714C4F67BFDD