CVE Published: 01/07/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024 Source: WPScan |
Vendor: Unknown |
Product: Quiz and Survey Master (QSM) Status : PUBLISHED
CVE-2024-4934 Description
The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in a page/post where the Quiz is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks