Sceawere

Vulnerability Detail

CVE-2026-96558UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored DOM-XSS in QSM

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
3h ago
Vendor
expresstech
Product
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'qsm_hidden_questions' parameter in all versions up to, and including, 11.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the attacker to force the mlw_results INSERT to fail by submitting an over-length or duplicate qsm_unique_key value, which triggers the audit trail code branch that writes the unescaped payload to wp_mlw_qm_audit_trail.form_data.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-10T07:16:42.343Z",
  "pubdate": "2026-10-10T07:16:42.343Z",
  "executiveSummary": "The Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker plugin for WordPress is susceptible to a Stored DOM-Based Cross-Site Scripting (XSS) vulnerability. Identified in all versions up to and including 11.2.6, this flaw originates from inadequate input sanitization and output escaping within the plugin's data processing logic.\nThe vulnerability allows unauthenticated attackers to inject malicious JavaScript payloads into the WordPress database. These payloads are subsequently executed in the browser of any user who accesses the compromised page, including administrative users. This effectively enables unauthorized actions, session hijacking, or the distribution of malicious content.\nExploitation requires a specific condition: the attacker must trigger a failure in the mlw_results database insertion process. This is typically achieved by submitting a malformed or duplicate qsm_unique_key, forcing the application to redirect execution to an insecure audit trail logging function. Once the payload resides in the database, it remains persistent until manually purged. Given that the vulnerability does not require administrative authentication, it poses a significant risk to the integrity and confidentiality of the WordPress installation.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper handling of the qsm_hidden_questions parameter during the audit trail logging process. When the application encounters a database error during the insertion of quiz results (specifically within the mlw_results table), it attempts to record the diagnostic information into the wp_mlw_qm_audit_trail database table via the form_data column.\nThe exploitation flow begins when an unauthenticated attacker submits a request designed to fail the primary INSERT operation. By providing an over-length or duplicate value for the qsm_unique_key parameter, the attacker forces the plugin's back-end logic to enter an error-handling branch. In this branch, the plugin captures the contents of the qsm_hidden_questions parameter without applying adequate sanitization or output escaping before persisting it to the wp_mlw_qm_audit_trail.form_data field.\nBecause the payload is stored directly in the database, the vulnerability manifests as Stored DOM-based XSS. When an administrator or authorized user views the audit logs or navigates to an affected page where this data is rendered, the unescaped script is injected into the document object model (DOM) and executed by the victim's browser. The malicious script runs within the security context of the victim's session, enabling the attacker to perform actions on behalf of the user, such as modifying plugin settings, creating new administrative accounts, or intercepting sensitive data such as session cookies.\nThe vulnerable component is the audit trail logging mechanism triggered by the Quiz and Survey Master plugin's result submission process. Since the mechanism is accessible to unauthenticated remote attackers, it provides a vector for full-scale XSS exploitation without prior platform access. The persistence of the payload ensures that the attack is not a one-time event; it remains resident in the database and triggers every time the audit trail is accessed, until the entry is explicitly removed by an administrator or the database is truncated. The lack of validation on the input parameter allows for arbitrary script injection, which is then rendered as HTML content, bypassing simple browser-level protections if the application does not implement robust Content Security Policy (CSP) headers or context-aware output encoding."
}
CVE-2026-96558: Stored DOM-XSS in QSM (HIGH Severity, CVSS: 7.2) | Sceawere