CVE-2025-67987
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows SQL Injection.This issue affects Quiz And Survey Master: from n/a through <= 10.3.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unauthenticated SQL injection in WordPress Quiz And Survey Master plugin (≤10.3.1) allows attackers to execute arbitrary SQL, risking data theft and site compromise.
The Quiz And Survey Master plugin for WordPress (quiz-master-next) suffers from an SQL injection vulnerability due to improper neutralization of special elements in SQL commands. Versions through 10.3.1 fail to sanitize user-supplied input before incorporating it into database queries, enabling the injection of malicious SQL statements [1].
Attackers can exploit this vulnerability without authentication by sending crafted HTTP requests to vulnerable endpoints. The lack of input validation allows an unauthenticated attacker to manipulate SQL queries, bypassing intended restrictions and accessing the database directly [1].
Successful exploitation could allow an attacker to read, modify, or delete arbitrary data from the WordPress database, including user credentials, posts, and configuration settings. This can lead to complete site compromise, privilege escalation, or data exfiltration. The vulnerability is considered highly dangerous and is expected to become part of mass-exploit campaigns targeting thousands of sites [1].
Mitigation requires updating the plugin to version 10.3.2 or later. If immediate update is not possible, applying a web application firewall rule or temporary disablement of the plugin is recommended. Patchstack offers mitigation rules to block attacks until patched [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=10.3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
1- SQL Injection Vulnerability in Quiz and Survey Master (QSM) Plugin Affecting 40k+ SitesPatchstack Blog · Jan 29, 2026