Record summary

CVE-2021-20792 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script via unspecified vectors.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE Listversions prior to 7.1.14affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Quiz and Survey Master <7.1.14 - Cross-Site ScriptingCVSS 6.1

WordPress Quiz and Survey Master plugin prior to 7.1.14 contains a cross-site scripting vulnerability which allows a remote attacker to inject arbitrary script via unspecified vectors.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the affected website, leading to potential data theft, session hijacking, or defacement.

Remediation

Update to the latest version of WordPress Quiz and Survey Master plugin (7.1.14) to mitigate the vulnerability.

WeaknessesCWE-79
AuthorsdhiyaneshDK
Template tagscve2021cvewordpresswp-pluginauthenticatedwpscanexpresstechvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:expresstech:quiz_and_survey_master:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

5