SQL Injection Flaw Affects 40,000 WordPress Sites
ID: f932bf89-d448-538e-83ed-1cd83107bed8
STIX ID: report--f932bf89-d448-538e-83ed-1cd83107bed8
Feed Name: Infosecurity Magazine (News)
Threat Score
A SQL injection vulnerability (CVE-2025-67987) in the Quiz and Survey Master (QSM) WordPress plugin allowed authenticated low-privilege users to inject SQL via the REST API 'is_linking' parameter, potentially exposing data on over 40,000 sites; Patchstack reported the issue and the vendor fixed it in QSM v10.3.2 following responsible disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
