CVE-2024-6879
Last modified
CVE-2024-6879 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before displaying them on a page or post where the Quiz is embedded, which could allows contributor and above roles to perform Stored Cross-Site Scripting (XSS) attacks.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before displaying them on a page or post where the Quiz is embedded, which could allows contributor and above roles to perform Stored Cross-Site Scripting (XSS) attacks.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Expresstech | Quiz And Survey Master | < 9.1.1 |
References
- https://wpscan.com/vulnerability/4da0b318-03e7-409d-9b02-f108e4232c87/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-6879?
How severe is CVE-2024-6879?
How do I fix CVE-2024-6879?
Are you affected by CVE-2024-6879?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
