
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67987 is a SQL Injection vulnerability in the Quiz And Survey Master (QSM) WordPress plugin developed by ExpressTech Systems. It affects all versions through 10.3.1 and was reported on November 21, 2025, by researcher Doan Dinh Van, with public disclosure on January 28, 2026. The vulnerability carries a CVSS v3.1 base score of 8.5 (High), reflecting its network-exploitable, low-privilege nature with high confidentiality impact (Patchstack, Feedly).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input is not properly sanitized before being incorporated into SQL queries. An authenticated attacker with low privileges (e.g., Subscriber role) can inject malicious SQL via the plugin's quiz or survey functionality, potentially manipulating database queries. The attack vector is network-based, requires no user interaction, and has a changed scope, indicating the impact extends beyond the vulnerable component itself. The vulnerability was discovered by Doan Dinh Van and assigned Patchstack ID 5ca9775273ac (Patchstack).
Successful exploitation allows an authenticated attacker to execute arbitrary SQL queries against the WordPress database, resulting in high confidentiality impact — including potential exposure of user credentials, quiz/survey data, and other sensitive site information. Availability is also partially affected (low impact), and the changed scope means the attack can affect resources beyond the plugin itself, such as the broader WordPress database. With approximately 40,000 active installations, the vulnerability poses a significant risk of mass exploitation campaigns targeting WordPress sites regardless of their size or traffic (Patchstack, Infosecurity Magazine).
As of the time of disclosure, no public proof-of-concept exploit code has been confirmed, and there is no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.021%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack has flagged it as high priority, noting that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting WordPress plugins (Patchstack).
inurl:wp-content/plugins/quiz-master-next).wp_users), configuration data, or other sensitive records stored in the database, potentially enabling privilege escalation or further site compromise (Patchstack)./wp-admin/admin-ajax.php or quiz submission URLs) containing SQL metacharacters such as ', --, UNION, SELECT, or SLEEP().UNION SELECT, information_schema, or wp_users table access originating from the web application user.The patched version of Quiz And Survey Master is 10.3.2, which resolves the SQL injection vulnerability — site administrators should update immediately (Patchstack). Patchstack users benefit from a virtual patch (mitigation rule) that blocks exploitation attempts until the plugin is updated. As additional hardening measures, restrict new user registrations if not required, apply the principle of least privilege to database accounts, and monitor database logs for anomalous SQL activity.
The vulnerability received notable coverage across security media, with Infosecurity Magazine, TechRadar, and The Hacker News highlighting the risk to over 40,000 WordPress sites (Infosecurity Magazine, TechRadar, The Hacker News). Wordfence included it in their weekly WordPress vulnerability report for the period of January 26–February 1, 2026 (Wordfence). Patchstack, which coordinated the disclosure, emphasized the mass-exploitation risk typical of SQL injection flaws in widely-used WordPress plugins (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."