05/31/2026
If your business website runs on WordPress, here’s a quick check for you 🔎
There’s a popular plugin called Quiz and Survey Master (QSM).
It’s used by more than 40,000 websites to create quizzes, surveys and forms without needing any coding.
Unfortunately, versions 10.3.1 and older were recently found to have a serious security flaw.
The issue is what’s known as an SQL injection vulnerability.
SQL is the language used to talk to a website’s database, the part that stores things like user accounts, submissions, and other important data.
An SQL injection flaw means someone can sneak malicious commands into that database.
In this case, any logged-in user, even someone with a basic subscriber account, could potentially inject commands into the system.
That could allow actions like:
🚫 Accessing sensitive data
🚫 Extracting information from the database
🚫 Manipulating content
The vulnerability is tracked as CVE-2025-67987, and it was fixed in version 10.3.2.
The latest version available is 10.3.5, which is the safest bet.
Based on WordPress.org data, just over half of websites using QSM are on version 10.3. That means a large number are likely still vulnerable.
That’s potentially tens of thousands of sites.
Right now, there’s no confirmed evidence of this flaw being actively exploited. But once a vulnerability is public, attackers often start scanning the internet looking for unpatched sites.