Back

CRITICAL

An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress

Published Jan 1, 2021

Description

An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an attacker to reinstall with a WordPress instance under their control. This occurred via qsm_remove_file_fd_question, which allowed unauthenticated deletions (even though it was only intended for a person to delete their own quiz-answer files).

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 1, 2021
Updated Aug 4, 2024
Reserved Jan 1, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a