Description
WordPress Plugin Quiz and Survey Master (QSM)-Easy Quiz and Survey Maker is prone to multiple vulnerabilities, including iFrame injection and input validation bypass vulnerabilities. Exploiting these issues could allow an attacker to inject iFrames in pages that will execute whenever a user accesses an injected page, or to send values other than the expected type. WordPress Plugin Quiz and Survey Master (QSM)-Easy Quiz and Survey Maker version 8.0.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 8.0.5 or latest
References
Related Vulnerabilities
WordPress Plugin Content Copy Protection & Prevent Image Save Cross-Site Request Forgery (1.3)
WordPress Plugin Eyes Only:User Access Shortcode Cross-Site Scripting (1.8.2)
WordPress Plugin Rockhoist Badges Cross-Site Scripting (1.2.2)
WordPress Plugin Subscribe Sidebar by Blubrry Cross-Site Scripting (1.3.1)
WordPress Plugin Alert Before Your Post Cross-Site Scripting (0.1.1)