Vulnerability record · CVE-2020-35951 · published 1 January 2021
CVE-2020-35951: Quiz and Survey Master plugin unauthenticated arbitrary file deletion
Expresstech · Quiz And Survey Master
The WordPress plugin Quiz and Survey Master before 7.0.1 exposes the qsm_remove_file_fd_question function without authentication, letting anyone delete arbitrary files on the server. Deleting files such as wp-config.php can take the site offline and enable an attacker to reinstall a WordPress instance they control. The flaw is a missing authentication check on a critical function (CWE-306).
Description
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an attacker to reinstall with a WordPress instance under their control. This occurred via qsm_remove_file_fd_question, which allowed unauthenticated deletions (even though it was only intended for a person to delete their own quiz-answer files).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
Automated analysis
critical priorityUnauthenticated network-reachable arbitrary file deletion with a CVSS score of 9.9 and very high EPSS probability, though not in KEV.
What it is
The WordPress plugin Quiz and Survey Master before 7.0.1 exposes the qsm_remove_file_fd_question function without authentication, letting anyone delete arbitrary files on the server. Deleting files such as wp-config.php can take the site offline and enable an attacker to reinstall a WordPress instance they control. The flaw is a missing authentication check on a critical function (CWE-306).
Impact
An unauthenticated attacker can delete arbitrary files, including wp-config.php, causing site outage and potentially enabling a full site takeover via reinstallation. Integrity and availability are directly affected; confidentiality impact is limited per the CVSS vector.
Attack surface
Reachable over the network through the plugin's file-removal endpoint with no authentication and no user interaction required, as reflected in the CVSS vector AV:N/AC:L/PR:N/UI:N. Any site running an affected version of the plugin is exposed.
Exploitation
The record is not listed in CISA KEV, but EPSS is very high (0.76328, 99.5th percentile) and multiple references are tagged Exploit, indicating public exploit code and active interest. No ransomware group usage is documented.
What to do
- Update the Quiz and Survey Master plugin to 7.0.1 or later immediately.
- If patching is not possible, disable or remove the plugin until it can be updated.
- Restrict access to plugin endpoints via WAF rules blocking unauthenticated requests to qsm_remove_file_fd_question.
- Verify wp-config.php and other critical files are intact and restore from backup if tampering is suspected.
- Rotate WordPress salts and administrative credentials if file deletion or reinstallation is suspected.
Detection
- Monitor web server logs for requests to plugin endpoints invoking qsm_remove_file_fd_question, especially from unauthenticated clients.
- Alert on deletion or modification events for wp-config.php and other core WordPress files.
- Watch for unexpected WordPress reinstallation activity or new administrative accounts.
- Correlate file integrity monitoring alerts with plugin-related HTTP requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://wpscan.com/vulnerability/10348 | ExploitThird Party Advisory |
| https://www.wordfence.com/blog/2020/08/critical-vulnerabilities-patched-in-quiz-and-survey-master-plugin/ | ExploitThird Party Advisory |
| https://wpscan.com/vulnerability/10348 | ExploitThird Party Advisory |
| https://www.wordfence.com/blog/2020/08/critical-vulnerabilities-patched-in-quiz-and-survey-master-plugin/ | ExploitThird Party Advisory |
Track CVE-2020-35951 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-35951), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.