CVE-2021-20792
WordPress Quiz and Survey Master <7.1.14 - Cross-Site Scripting
Record summary
CVE-2021-20792 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script via unspecified vectors.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Quiz And Survey MasterBrowse ExpressTech / Quiz And Survey Master | CVE List | versions prior to 7.1.14 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Quiz and Survey Master <7.1.14 - Cross-Site ScriptingCVSS 6.1
WordPress Quiz and Survey Master plugin prior to 7.1.14 contains a cross-site scripting vulnerability which allows a remote attacker to inject arbitrary script via unspecified vectors.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the affected website, leading to potential data theft, session hijacking, or defacement.
Remediation
Update to the latest version of WordPress Quiz and Survey Master plugin (7.1.14) to mitigate the vulnerability.
Source: ProjectDiscovery