Expresstech maintains a modest portfolio of WordPress plugins focused on interactive content and navigation functionality, notably Quiz and Survey Master and Responsive Menu, which serve a distributed user base across numerous WordPress installations. Despite the narrow product scope, these plugins occupy a prominent position in the WordPress ecosystem due to their widespread adoption and deep integration into site architecture. The recurring vulnerability patterns center on web-application input-handling and authorization issues—cross-site scripting, SQL injection, CSRF, missing authorization checks, and unrestricted file uploads—which are characteristic of plugin-level exposure in a content-management environment where trust boundaries between administrator and user input are frequently breached. A meaningful share of the vendor's disclosures reach serious severity, reflecting the potential for authenticated and unauthenticated attackers to compromise site integrity and user data. Defenders should treat Expresstech plugin updates as part of routine WordPress maintenance and monitor for upstream patches, particularly on internet-facing sites; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Expresstech over time
Signals from CVEs in this vendor scope (50 CVEs).
50 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35951CRITICAL An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effective | Jan 1, 2021 | 9.9 | 80 | NO | YES |
CVE-2023-28787CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: | Mar 26, 2024 | 9.3 | 39 | NO | YES |
CVE-2022-41652CRITICAL Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress. | Nov 18, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-20792MEDIUM Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script via unspecified vectors. | Aug 18, 2021 | 6.1 | 31 | NO | YES |
CVE-2020-35949CRITICAL An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve rem | Jan 1, 2021 | 9.8 | 30 | NO | NO |
CVE-2023-0291CRITICAL The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJA | Jun 9, 2023 | 9.1 | 29 | NO | NO |
CVE-2021-24160HIGH In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ | Apr 5, 2021 | 8.8 | 29 | NO | NO |
CVE-2026-40787HIGH Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.0.0 versions. | Jun 15, 2026 | 7.1 | 28 | NO | NO |
CVE-2021-36906HIGH Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress. | Nov 3, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-0180HIGH Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduc | Jan 17, 2022 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (50 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Expresstech.
Media articles that mention a CVE ID that affects a product developed by Expresstech — matched by CVE ID, not by vendor name.