php/qmnoptionsquestionstab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant stored XSS, via the questionname parameter because js/admin_question.js mishandles parsing inside of a SCRIPT element.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-11085.json"