CRITICAL

CVE-2020-35951

CVSS v3

9.9

CRITICAL

EPSS Score

58.2%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an attacker to reinstall with a WordPress instance under their control. This occurred via qsm_remove_file_fd_question, which allowed unauthenticated deletions (even though it was only intended for a person to delete their own quiz-answer files).

Technical details

Published
1/1/2021

Frequently asked questions

What is CVE-2020-35951?

An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an attacker to reinstall with a WordPress instance under their control. This occurred via qsm_remove_file_fd_question, which allowed unauthenticated deletions (even though it was only intended for a person to delete their own quiz-answer files).

Is CVE-2020-35951 actively exploited?

Active exploitation of CVE-2020-35951 has not been confirmed. The EPSS score is 58.2%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-35951?

CVE-2020-35951 has a CVSS v3 base score of 9.9 (CRITICAL severity).

Is CVE-2020-35951 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.