CVE-2020-35951 Scanner

Detects 'Arbitrary File Deletion' vulnerability in Quiz and Survey Master plugin for Wordpress affects v. before 7.0.1.


The Quiz and Survey Master plugin for WordPress is a popular tool used by many website owners to create exams, surveys, and quizzes. It's an interactive plugin that offers various question formats, customizable themes, and reporting features. With Quiz and Survey Master, website owners can easily create engaging content for their audience.

However, recently, a vulnerability was detected in the plugin. CVE-2020-35951 allows users to delete files, including the wp-config.php, via the qsm_remove_file_fd_question function. This vulnerability exposes site owners to the risk of a takeover by hackers who could install their version of a WordPress instance. Even though this function was only designed for users to delete their own quiz-answer files, unauthorized access can erase all files, taking the site offline temporarily or permanently.

Exploiting this vulnerability can lead to serious consequences. Hackers can steal confidential data, such as customer information, financial details, and website credentials. They can even redirect the website to a malicious page, steal website traffic, and conduct a ransomware attack. These attacks come with severe legal and financial implications, including loss of reputation, revenue, and customer trust.

