EIP-2026-113994

PRE-CVE

WordPress Plugin Quiz And Survey Master 4.5.4/4.7.8 - Cross-Site Request Forgery

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113994. PoCs published by dxw.

AI-analyzed exploit summary This exploit demonstrates a CSRF/stored XSS vulnerability in Quiz And Survey Master (formerly Quiz Master Next) versions 4.5.4 and 4.7.8. The vulnerability allows unauthenticated attackers to inject malicious JavaScript via the question_name parameter, bypassing WordPress's esc_js() escaping due to improper handling in the admin_question.js file.

Description

WordPress Plugin Quiz And Survey Master 4.5.4/4.7.8 - Cross-Site Request Forgery

Exploits (1)

exploitdb WORKING POC
by dxw · htmlwebappsphp
https://www.exploit-db.com/exploits/40934

This exploit demonstrates a CSRF/stored XSS vulnerability in Quiz And Survey Master (formerly Quiz Master Next) versions 4.5.4 and 4.7.8. The vulnerability allows unauthenticated attackers to inject malicious JavaScript via the question_name parameter, bypassing WordPress's esc_js() escaping due to improper handling in the admin_question.js file.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Quiz And Survey Master (formerly Quiz Master Next) versions 4.5.4, 4.7.8
No auth needed
Prerequisites: Target must have the vulnerable plugin installed and activated · Attacker must lure a victim to a crafted page or submit the form via CSRF
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026