CVE-2025-6790
14.08.2025, 06:15
The Quiz and Survey Master (QSM) WordPress plugin before 10.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.