More than 40,000 WordPress sites affected by new malware flaw – find out if you’re affected


  • An SQL injection bug was found in QSM plugin version 10.3.1 and below
  • Vulnerability allows logged in users (subscriber or higher) to extract sensitive database data
  • WordPress admins are encouraged to update QSM to v10.3.2 or later to mitigate the risk

If your site is running the Quiz and Survey Master WordPress plugin, you may want to update it to the latest version or risk a possible cyber attack.

QSM lets users create quizzes, surveys and forms without coding, with more than 40,000 sites actively using it – but recently it was discovered that versions 10.3.1 and earlier were vulnerable to an SQL injection flaw that allowed any logged-in user to inject commands into the database.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top