<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Quiz and Survey Master (QSM) – Quiz Maker &amp; Survey Maker (&lt;= 11.2.6) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/quiz-and-survey-master-qsm--quiz-maker--survey-maker--11.2.6/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 07:52:55 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/quiz-and-survey-master-qsm--quiz-maker--survey-maker--11.2.6/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored DOM-Based XSS in Quiz and Survey Master WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-qsm-xss/</link><pubDate>Sat, 10 Oct 2026 07:52:55 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-qsm-xss/</guid><description>An unauthenticated stored XSS vulnerability in the Quiz and Survey Master plugin allows attackers to inject arbitrary web scripts by triggering a database error in the audit trail logging mechanism.</description><content:encoded><![CDATA[<p>The Quiz and Survey Master (QSM) - Quiz Maker &amp; Survey Maker plugin for WordPress, in versions up to and including 11.2.6, is vulnerable to Stored DOM-Based Cross-Site Scripting (XSS). The vulnerability exists due to insufficient input sanitization and output escaping within the 'qsm_hidden_questions' parameter.</p>
<p>An unauthenticated attacker can exploit this by manipulating the submission process. By forcing the 'mlw_results' database insert to fail, typically by providing an oversized or duplicate 'qsm_unique_key' value, the application enters an error-handling code path. Within this specific audit trail code branch, the application writes the unescaped payload from the 'qsm_hidden_questions' parameter into the 'wp_mlw_qm_audit_trail.form_data' database table. When an administrator or user subsequently views the affected entry, the injected script executes in the context of their session, potentially leading to unauthorized actions or credential theft.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the victim's browser context. This can lead to account takeover, sensitive data exfiltration, or the performance of administrative actions on behalf of the victim. Given the nature of WordPress plugins, this vulnerability affects any site running QSM versions 11.2.6 or earlier.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch the Quiz and Survey Master (QSM) plugin by upgrading to a version later than 11.2.6 immediately.</li>
<li>Monitor webserver access logs for anomalous POST requests to the QSM plugin endpoints, specifically looking for abnormally long 'qsm_unique_key' values or repetitive submissions targeting audit trail functionality.</li>
<li>Implement Content Security Policy (CSP) headers to mitigate the impact of potential XSS by restricting the sources from which scripts can be executed.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>