CVE-2025-67987
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67987 is a SQL Injection vulnerability in the Quiz And Survey Master (QSM) WordPress plugin developed by ExpressTech Systems. It affects all versions through 10.3.1 and was reported on November 21, 2025, by researcher Doan Dinh Van, with public disclosure on January 28, 2026. The vulnerability carries a CVSS v3.1 base score of 8.5 (High), reflecting its network-exploitable, low-privilege nature with high confidentiality impact (Patchstack, Feedly).

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input is not properly sanitized before being incorporated into SQL queries. An authenticated attacker with low privileges (e.g., Subscriber role) can inject malicious SQL via the plugin's quiz or survey functionality, potentially manipulating database queries. The attack vector is network-based, requires no user interaction, and has a changed scope, indicating the impact extends beyond the vulnerable component itself. The vulnerability was discovered by Doan Dinh Van and assigned Patchstack ID 5ca9775273ac (Patchstack).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary SQL queries against the WordPress database, resulting in high confidentiality impact — including potential exposure of user credentials, quiz/survey data, and other sensitive site information. Availability is also partially affected (low impact), and the changed scope means the attack can affect resources beyond the plugin itself, such as the broader WordPress database. With approximately 40,000 active installations, the vulnerability poses a significant risk of mass exploitation campaigns targeting WordPress sites regardless of their size or traffic (Patchstack, Infosecurity Magazine).

Exploitability

As of the time of disclosure, no public proof-of-concept exploit code has been confirmed, and there is no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.021%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack has flagged it as high priority, noting that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting WordPress plugins (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Quiz And Survey Master plugin version 10.3.1 or earlier using tools like WPScan, Shodan, or Google dorks (e.g., inurl:wp-content/plugins/quiz-master-next).
  2. Obtain low-privilege access: Register or obtain a Subscriber-level account on the target WordPress site, as the vulnerability requires authenticated access with low privileges.
  3. Identify injectable parameter: Interact with quiz or survey submission endpoints provided by the QSM plugin and identify input fields or parameters that are passed to SQL queries without proper sanitization.
  4. Craft SQL injection payload: Inject malicious SQL syntax (e.g., UNION-based, boolean-based blind, or time-based blind payloads) into the vulnerable parameter to enumerate database tables, extract credentials, or retrieve sensitive data.
  5. Exfiltrate data: Use the SQL injection to dump WordPress user table hashes (wp_users), configuration data, or other sensitive records stored in the database, potentially enabling privilege escalation or further site compromise (Patchstack).

Indicators of compromise

  • Network: Unusual or malformed HTTP POST/GET requests to QSM plugin endpoints (e.g., paths under /wp-admin/admin-ajax.php or quiz submission URLs) containing SQL metacharacters such as ', --, UNION, SELECT, or SLEEP().
  • Logs: WordPress or web server access logs showing repeated requests to QSM-related endpoints with encoded or obfuscated SQL payloads; database error messages logged related to malformed SQL queries.
  • Database: Unexpected queries in MySQL general query logs involving UNION SELECT, information_schema, or wp_users table access originating from the web application user.
  • File System: Presence of newly created PHP webshells or backdoor files in the WordPress uploads or plugin directories following exploitation.

Mitigation and workarounds

The patched version of Quiz And Survey Master is 10.3.2, which resolves the SQL injection vulnerability — site administrators should update immediately (Patchstack). Patchstack users benefit from a virtual patch (mitigation rule) that blocks exploitation attempts until the plugin is updated. As additional hardening measures, restrict new user registrations if not required, apply the principle of least privilege to database accounts, and monitor database logs for anomalous SQL activity.

Community reactions

The vulnerability received notable coverage across security media, with Infosecurity Magazine, TechRadar, and The Hacker News highlighting the risk to over 40,000 WordPress sites (Infosecurity Magazine, TechRadar, The Hacker News). Wordfence included it in their weekly WordPress vulnerability report for the period of January 26–February 1, 2026 (Wordfence). Patchstack, which coordinated the disclosure, emphasized the mass-exploitation risk typical of SQL injection flaws in widely-used WordPress plugins (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management