The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and including, 8.0.8. This makes it possible for unauthenticated attackers to delete arbitrary media files.
https://wordpress.org/plugins/quiz-master-next/
https://plugins.trac.wordpress.org/changeset/2834471/quiz-master-next
https://packetstormsecurity.com/files/171011/wpqsm808-xsrf.txt