CVE-2026-2412 | expresstech Quiz and Survey Master Plugin up to 10.3.5 on WordPress Parameter sanitize_text_field wpdb sql injection
A vulnerability was found in expresstech Quiz and Survey Master Plugin up to 10.3.5 on WordPress. It has been rated as critical. This issue affects the function sanitize_text_field of the component Parameter Handler. Performing a manipulation of the argument wpdb results in sql injection.
This vulnerability was named CVE-2026-2412. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.