← WordPress Vulnerabilities
WordPress security by component

Quiz and Survey Master (QSM)

Quiz and Survey Master (QSM) is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 5.3.

Plugin slug: quiz-and-survey-master-qsm

CVE-2026-14821: Quiz and Survey Master contributors can delete output templates

Quiz and Survey Master before 11.1.5 omits a capability check from its output-template deletion operation. Any authenticated Contributor can select and delete arbitrary QSM output templates, allowing a low-privilege account to disrupt or alter quiz and survey presentation. The WPScan CNA record does not disclose the endpoint, action, template identifier parameter or deletion function.

PublishedJul 28, 2026
Known safe version11.1.5
Safe version
Jul 28, 2026 CVE-2026-14821
Quiz and Survey Master contributors can delete output templates
Quiz and Survey Master before 11.1.5 omits a capability check from its output-template deletion operation. Any authenticated Contributor can select and delete arbitrary QSM output templates, allowing a low-privilege account to disrupt or alter quiz and survey presentation. The WPScan CNA record does not disclose the endpoint, action, template identifier parameter or deletion function.
11.1.5
CVE2.7
NVDPending
Jul 27, 2026 CVE-2026-14820
Quiz and Survey Master credential checks enable account enumeration and brute force
Quiz and Survey Master before 11.1.3 exposes a front-end credential-check flow without rate limiting or useful audit controls and returns distinguishable responses for valid and invalid users. An unauthenticated attacker can use those response differences to enumerate usernames and repeatedly test passwords, potentially taking over an account whose credentials are guessed. The CNA record does not disclose the route, action, parameter names or validation function.
11.1.3
CVE5.3
NVDPending
Aug 14, 2025 CVE-2025-6790
Quiz and Survey Master (QSM): Cross-site request forgery
Quiz and Survey Master (QSM) is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending