CVE-2025-67987Disclosure

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows SQL Injection.This issue affects Quiz And Survey Master: from n/a through <= 10.3.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-03); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-03: 2Mentions · 2026-02-10: 1Mentions · 2026-02-22: 1Patch / Workaround · 2026-02-03: 1Patch / Workaround · 2026-02-10: 1Technical Details · 2026-02-03: 2Technical Details · 2026-02-10: 1Technical Details · 2026-02-22: 102-0302-1002-22
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-032
Disclosure1Patch1
2026-02-101
Disclosure1
2026-02-221
Disclosure1
Full discourse4 posts
  • kokumօtօ@__kokumoto
    Disclosure

    4万以上のWordPressサイトが使用するQuiz and Survey MasterプラグインにSQLインジェクションの脆弱性(CVE-2025-67987)。要認証だが管理者権限は不要。is_linkingパラメータの無害化漏れ。 https://www.infosecurity-magazine.com/news/wordpress-sql-injection-flaw-40000/

    Post summary

    The post reports a SQL injection flaw (CVE-2025-67987) in the Quiz and Survey Master WordPress plugin, used by over 40,000 sites, requiring authentication but no admin rights, and highlights a sanitization issue with the is_linking parameter.

    00012726
    7.2K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    WordPress Quiz and Survey Master の脆弱性 CVE-2025-67987 が FIX:4 万超のサイトに影響 https://iototsecnews.jp/2026/02/03/sql-injection-flaw-affects-40000-wordpress-sites/ この問題の原因は、利用者から送られてくるデータは必ず正しい形式 (数字) であると想定するアンケート作成ツールが、その内容をチェックせずにデータベースへの命令文 (SQL) に直接組み込んでしまったことにあります。それにより、”is_linking” という設定項目を介して、数字ではなくデータベースを操作する悪意の命令が送信されると、システムがそれを命令の一部として実行してしまいます。これが、SQLインジェクションと呼ばれる脆弱性です。この問題の深刻な点は、管理者ではない一般のログインユーザーであっても、この欠陥を突いてデータベース内の機密情報を盗み出せてしまう点にあります。ご利用のチームは、ご注意ください。 #CVE202567987 #Plugin #QuizandSurveyMaster #Vulnerability #WordPress

    Post summary

    The article discloses a SQL injection flaw (CVE‑2025‑67987) in WordPress Quiz and Survey Master, notes that a fix is available for over 40,000 sites, and describes how the vulnerability can be exploited by non‑admin users.

    01000148
    483 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-67987 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allo… https://www.cve.org/CVERecord?id=CVE-2025-67987

    Post summary

    The text announces CVE-2025-67987, an SQL injection vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next, providing technical details but no PoC, exploit, or patch information.

    00000218
    56.5K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 40K+ WordPress sites at risk from Quiz and Survey Master (QSM) SQL injection flaw (CVE-2025-67987) A SQL injection bug in the Quiz and Survey Master (QSM) plugin (versions ≤ 10.3.1) can be abused by low-privilege logged-in users to query/alter the WordPress database, potentially exposing or tampering with site data. Update immediately to v10.3.2+ and review logs for suspicious requests to plugin endpoints and unexpected DB activity. 🎯 Target: Global/WordPress #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.infosecurity-magazine.com/news/wordpress-sql-injection-flaw-40000/

    Post summary

    A SQL injection flaw in the Quiz and Survey Master plugin (CVE‑2025‑67987) threatens over 40,000 WordPress sites, enabling low‑privilege users to execute arbitrary database queries; the advisory urges immediate upgrade to v10.3.2+ and vigilant log monitoring.

    0000038
    192 followersView on X

Explore more