31/05/2026
If your business website runs on WordPress, here’s a quick check for you 🔎
There’s a popular plugin called Quiz and Survey Master (QSM).
It’s used by more than 40,000 websites to create quizzes, surveys and forms without needing any coding.
Unfortunately, versions 10.3.1 and older were recently found to have a serious security flaw.
The issue is what’s known as an SQL injection vulnerability.
SQL is the language used to talk to a website’s database, the part that stores things like user accounts, submissions, and other important data.
An SQL injection flaw means someone can sneak malicious commands into that database.
In this case, any logged-in user, even someone with a basic subscriber account, could potentially inject commands into the system.
That could allow actions like:
🚫 Accessing sensitive data
🚫 Extracting information from the database
🚫 Manipulating content
The vulnerability is tracked as CVE-2025-67987, and it was fixed in version 10.3.2.
The latest version available is 10.3.5, which is the safest bet.
Based on WordPress.org data, just over half of websites using QSM are on version 10.3. That means a large number are likely still vulnerable.
That’s potentially tens of thousands of sites.
Right now, there’s no confirmed evidence of this flaw being actively exploited. But once a vulnerability is public, attackers often start scanning the internet looking for unpatched sites.
👉 If your site uses this plugin, the solution is straightforward: Update it immediately 👈
More broadly, this is a reminder of something I say often to business owners: WordPress itself isn’t usually the weak link. It’s the plugins.
Every plugin you install adds functionality, but also adds potential risk.
If you’re not actively using a plugin or theme, it shouldn’t just be deactivated. It should be deleted from the server completely.
Websites aren’t a set and forget asset. They’re part of your digital infrastructure.
If they’re vulnerable, they can become an entry point into your wider systems. Especially if admin accounts reuse passwords across services.
❓ When was the last time someone checked which plugins your website is running and whether they’re fully up to date?