PT-2025-50054 · Expresstech Systems+1 · Quiz/Survey Master+1

CVE-2025-63054

·

Published

2025-11-30

·

Updated

2025-12-09

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Quiz And Survey Master versions prior to 10.3.3
Description Incorrectly configured access control security levels in the Quiz And Survey Master plugin for WordPress allow unauthorized access. This is caused by a missing capability check in a function, enabling unauthenticated attackers to perform unauthorized actions.
Recommendations Update to a version newer than 10.3.2.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-63054

Affected Products

Quiz/Survey Master
Quiz-Master-Next