Description
WordPress Plugin Quiz and Survey Master (QSM)-Easy Quiz and Survey Maker is prone to multiple vulnerabilities, including iFrame injection and input validation bypass vulnerabilities. Exploiting these issues could allow an attacker to inject iFrames in pages that will execute whenever a user accesses an injected page, or to send values other than the expected type. WordPress Plugin Quiz and Survey Master (QSM)-Easy Quiz and Survey Maker version 8.0.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 8.0.5 or latest
References
Related Vulnerabilities
WordPress 4.5.x Cross-Site Scripting Vulnerability (4.5 - 4.5.1)
PHP Improper Restriction of XML External Entity Reference Vulnerability (CVE-2013-1824)
Jboss EAP CVE-2013-1862 Vulnerability (CVE-2013-1862)
WebLogic CVE-2021-2403 Vulnerability (CVE-2021-2403)
Sqlite NULL Pointer Dereference Vulnerability (CVE-2019-9937)