Sceawere

Vulnerability Detail

CVE-2026-97289UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Quiz And Survey Master XSS

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
ExpressTech Systems
Product
Quiz And Survey Master
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-09-30T13:17:39.210Z",
  "pubdate": "2026-09-30T13:17:39.210Z",
  "executiveSummary": "The Quiz And Survey Master plugin for WordPress, specifically versions 11.2.6 and below, contains an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.\nThis security flaw allows remote, unauthenticated attackers to inject malicious JavaScript into the victim's browser context via crafted HTTP requests targeting specific plugin parameters.\nThe vulnerability arises due to insufficient input validation and output encoding of user-supplied data before rendering it in the DOM.\nSuccessful exploitation permits the execution of arbitrary scripts in the session of a user viewing the affected page.\nPotential impacts include session hijacking, unauthorized actions performed on behalf of the user, sensitive data exfiltration, or the redirection of users to malicious third-party domains.\nBecause the vulnerability does not require authentication, the attack surface is wide, exposing any WordPress instance utilizing the plugin to potential compromise by unauthorized external actors.",
  "technicalDetails": "The vulnerability resides in the way Quiz And Survey Master handles URL parameters or form inputs during the processing of quiz or survey interactions. The plugin fails to sanitize user-supplied data reflected back to the client, leading to a classic Reflected XSS scenario.\nRoot cause analysis identifies a failure to implement robust output encoding (e.g., using WordPress escape functions like esc_html() or esc_js()) on reflected plugin parameters. When a user navigates to a URL containing a crafted malicious payload in the vulnerable parameter, the application echoes this input directly into the HTML response stream.\nAttack Flow: An attacker constructs a specialized URL containing a JavaScript payload within the vulnerable query parameter. This URL is then distributed to targets, perhaps via social engineering or embedded links on third-party websites. When an unsuspecting user clicks the link, their browser submits the request to the target WordPress site. The server processes the request and embeds the unencoded payload into the resulting HTML page returned to the client. Upon receiving the response, the browser interprets the malicious script as legitimate content from the trusted origin, executing the code within the security context of the user's session.\nExploitation requirements include the ability to craft an HTTP request that targets the vulnerable endpoint and successfully convince a user to navigate to the malicious URL. Since the vulnerability is unauthenticated, no prior site access or privilege escalation is required to initiate the attack.\nPayload behavior involves manipulating the Document Object Model (DOM), such as reading session cookies (if not protected by HttpOnly flags), performing unauthorized actions via asynchronous requests (CSRF-like behavior), or modifying site content dynamically to deceive the user. The impact is persistent as long as the user's session remains active and the browser processes the injected script. Post-exploitation impact varies depending on the victim's role, as an administrator clicking the link could potentially lead to full site compromise if the script includes commands to create new administrative accounts or modify plugin settings."
}
CVE-2026-97289: Quiz And Survey Master XSS (HIGH Severity, CVSS: 7.1) | Sceawere