CVE-2025-9318 | Quiz and Survey Master QSM Plugin up to 10.3.1 on WordPress Query Parameter is_linking sql injection
A vulnerability, which was classified as critical, has been found in Quiz and Survey Master QSM Plugin up to 10.3.1 on WordPress. Affected by this vulnerability is an unknown functionality of the component Query Parameter Handler. Performing a manipulation of the argument is_linking results in sql injection.
This vulnerability is cataloged as CVE-2025-9318. It is possible to initiate the attack remotely. There is no exploit available.