CyberRota Analysis
AI-GeneratedThe Quiz and Survey Master plugin for WordPress prior to version 11.2.4 is vulnerable due to insufficient authorization checks in its REST API, enabling users with a Contributor role to access sensitive quiz data, including questions and correct answers, belonging to other users. This exposure could lead to unauthorized information disclosure, potentially compromising quiz integrity and user privacy. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of data leakage.
Original NVD Description
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allowing users with a role as low as Contributor to read the questions, hints and correct answer keys of quizzes belonging to other users.