S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-20792 Scanner

CVE-2021-20792 scanner - Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.3k
Times Used
continuous scan runs
3.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-20792
6.1
CVSS

Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script via unspecified vectors.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Quiz And Survey Masterby ExpressTech
versions prior to 7.1.14
Updated Aug 21, 2026View on NVD →
Detail

ExpressTech Quiz And Survey Master is a well-known WordPress plugin that is widely used for creating quizzes and surveys on websites. The plugin is popular among businesses, educational institutions, and individuals who seek to engage their target audience by offering them interactive quizzes and surveys. With its user-friendly interface and extensive customization options, this plugin has become a go-to solution for website owners who want to create engaging and interactive content.

However, Quiz And Survey Master was recently found to have a critical vulnerability that could have severe repercussions for website owners and their users. The vulnerability, identified as CVE-2021-20792, allows remote attackers to inject arbitrary script via unspecified vectors. This means that attackers could gain access to user data, bypass authentication mechanisms, perform actions on behalf of the user, or even take complete control over the website.

When exploited, this vulnerability can compromise the security of a website and its users. Attackers could use it to steal sensitive data, spread malware, or launch phishing attacks. This puts website owners and their users at risk of financial losses, reputational damage, and other negative consequences.

Thanks to the pro features of the s4e.io platform, website owners can easily and quickly learn about vulnerabilities in their digital assets. The platform offers comprehensive security scanning for websites, web applications, and APIs, as well as actionable insights and expert guidance to help businesses and individuals improve their security posture. With s4e.io, website owners can stay one step ahead of attackers and protect their digital assets from cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners can take several precautions, including:

  • Updating the Quiz And Survey Master plugin to the latest version as soon as possible
  • Ensuring that all plugins and themes on the website are up-to-date
  • Using strong passwords for all user accounts, especially admin accounts
  • Enabling two-factor authentication for all user accounts
  • Regularly scanning the website for vulnerabilities using a security scanner

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.