← Vulnerability feed

Vulnerability record · CVE-2020-35951 · published 1 January 2021

CVE-2020-35951: Quiz and Survey Master plugin unauthenticated arbitrary file deletion

Expresstech · Quiz And Survey Master

The WordPress plugin Quiz and Survey Master before 7.0.1 exposes the qsm_remove_file_fd_question function without authentication, letting anyone delete arbitrary files on the server. Deleting files such as wp-config.php can take the site offline and enable an attacker to reinstall a WordPress instance they control. The flaw is a missing authentication check on a critical function (CWE-306).

9.9 CVSS 3.1 Critical EPSS 76% · top 0.5% CWE-306 · Missing authentication for critical function
9.9CVSS 3.1 base score, v2 6.4
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an attacker to reinstall with a WordPress instance under their control. This occurred via qsm_remove_file_fd_question, which allowed unauthenticated deletions (even though it was only intended for a person to delete their own quiz-answer files).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable arbitrary file deletion with a CVSS score of 9.9 and very high EPSS probability, though not in KEV.

What it is

The WordPress plugin Quiz and Survey Master before 7.0.1 exposes the qsm_remove_file_fd_question function without authentication, letting anyone delete arbitrary files on the server. Deleting files such as wp-config.php can take the site offline and enable an attacker to reinstall a WordPress instance they control. The flaw is a missing authentication check on a critical function (CWE-306).

Impact

An unauthenticated attacker can delete arbitrary files, including wp-config.php, causing site outage and potentially enabling a full site takeover via reinstallation. Integrity and availability are directly affected; confidentiality impact is limited per the CVSS vector.

Attack surface

Reachable over the network through the plugin's file-removal endpoint with no authentication and no user interaction required, as reflected in the CVSS vector AV:N/AC:L/PR:N/UI:N. Any site running an affected version of the plugin is exposed.

Exploitation

The record is not listed in CISA KEV, but EPSS is very high (0.76328, 99.5th percentile) and multiple references are tagged Exploit, indicating public exploit code and active interest. No ransomware group usage is documented.

What to do

  • Update the Quiz and Survey Master plugin to 7.0.1 or later immediately.
  • If patching is not possible, disable or remove the plugin until it can be updated.
  • Restrict access to plugin endpoints via WAF rules blocking unauthenticated requests to qsm_remove_file_fd_question.
  • Verify wp-config.php and other critical files are intact and restore from backup if tampering is suspected.
  • Rotate WordPress salts and administrative credentials if file deletion or reinstallation is suspected.

Detection

  • Monitor web server logs for requests to plugin endpoints invoking qsm_remove_file_fd_question, especially from unauthenticated clients.
  • Alert on deletion or modification events for wp-config.php and other core WordPress files.
  • Watch for unexpected WordPress reinstallation activity or new administrative accounts.
  • Correlate file integrity monitoring alerts with plugin-related HTTP requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-35951 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-41652Expresstech quiz and survey master improper access control vulnerabilityBypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.EPSS 0.75%9.8CVE-2020-35949Expresstech quiz and survey master unrestricted file upload vulnerabilityAn issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload …EPSS 5.1%9.1CVE-2023-0291Expresstech quiz and survey master missing authorization vulnerabilityThe Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the …EPSS 2.0%8.8CVE-2024-5606Expresstech quiz and survey master sql injection vulnerabilityThe Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_d…EPSS 0.59%8.8CVE-2023-26524Expresstech quiz and survey master cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0…EPSS 0.31%8.8CVE-2022-46862Expresstech quiz and survey master cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0…EPSS 0.38%8.8CVE-2021-36906Expresstech quiz and survey master insecure direct object reference vulnerabilityMultiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress.EPSS 0.58%8.8CVE-2022-0180Expresstech quiz and survey master cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authenticati…EPSS 0.65%

Source: NIST National Vulnerability Database (record CVE-2020-35951), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.