logo

SQL Injection Flaw Affects 40,000 WordPress Sites

ID: f932bf89-d448-538e-83ed-1cd83107bed8

STIX ID: report--f932bf89-d448-538e-83ed-1cd83107bed8

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-02-03

Date Updated: 2026-04-22

...
...

A SQL injection vulnerability (CVE-2025-67987) in the Quiz and Survey Master (QSM) WordPress plugin allowed authenticated low-privilege users to inject SQL via the REST API 'is_linking' parameter, potentially exposing data on over 40,000 sites; Patchstack reported the issue and the vendor fixed it in QSM v10.3.2 following responsible disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.