SQL injection bug in Quiz and Survey Master puts 40,000 WordPress sites at risk

March 23, 20262 min read2 sources
Share:
SQL injection bug in Quiz and Survey Master puts 40,000 WordPress sites at risk

A SQL injection vulnerability in the WordPress plugin Quiz and Survey Master (QSM) affects roughly 40,000 sites, according to a report by Infosecurity Magazine. The flaw could let attackers interfere with database queries on vulnerable installations, creating a path to data theft, content tampering, or broader site compromise depending on how the plugin is deployed and what database permissions are available.

QSM is used to build quizzes, surveys and tests on WordPress sites. Security issues in plugins like this can have outsized reach because one bug can expose thousands of websites at once. In this case, the concern is not WordPress core but a third-party plugin with a large install base.

Infosecurity Magazine reported the issue as an SQL injection flaw but did not, in the cited item, provide full technical details such as the exact vulnerable version range, whether the bug requires authentication, or whether active exploitation has been observed. Those details matter: unauthenticated SQL injection flaws are generally more dangerous because they can be triggered remotely without a valid account.

Even without confirmed exploitation, SQL injection remains one of the most serious web application weaknesses. In WordPress environments, plugin-level SQL injection can expose usernames, email addresses, password hashes, stored survey responses and other site data. In worse cases, attackers may be able to alter site settings, inject malicious content or create administrator-level access through database manipulation.

Site owners using Quiz and Survey Master should review the plugin's changelog, update immediately to the latest available version, and check web and database logs for suspicious requests to plugin-related endpoints. Administrators should also review for unexpected user accounts, content changes and signs of follow-on abuse. Organizations managing multiple WordPress properties should verify whether QSM is installed anywhere in their estate and prioritize patching exposed systems.

The incident is another reminder that plugin security remains one of the biggest risks in the WordPress ecosystem, where a single coding flaw can quickly become a mass-exposure problem across thousands of sites.

Share:

// SOURCES

// RELATED

Meta settles bellwether lawsuit alleging addictive design harmed student mental health

Meta's confidential settlement with a Washington school district marks a pivotal moment in the massive litigation against social media's psychological

6 min readMay 24

Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network

A sophisticated zero-day attack on Huawei routers allegedly caused Luxembourg's 2023 national telecom outage, raising severe global security concerns.

6 min readMay 23

MiniPlasma Windows 0-day enables SYSTEM privilege escalation on fully patched systems

A newly disclosed 0-day flaw, MiniPlasma, allows attackers to gain full SYSTEM control on patched Windows systems, with a public PoC accelerating risk

6 min readMay 18

The ransomware dilemma: why more than half of security chiefs would pay the price

A new survey reveals 56% of CISOs would consider paying a ransom, highlighting the intense pressure to restore operations despite official guidance.

6 min readMay 16