← WordPress Vulnerabilities
WordPress security by component

Quiz and Survey Master (QSM)

Quiz and Survey Master (QSM) is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 5.3.

Plugin slug: quiz-and-survey-master-qsm

CVE-2026-14824: QSM question settings permit Contributor stored XSS

Quiz and Survey Master before 11.2.2 outputs a question setting into an unquoted HTML attribute without proper escaping. A Contributor can store a value that breaks out of the attribute and injects JavaScript, which executes for any user who views the affected quiz. The public advisory does not disclose the setting, save endpoint, request parameter, output attribute or rendering function.

PublishedAug 04, 2026
Known safe version11.2.2
Published vulnerabilities for quiz-and-survey-master-qsm
Safe version
Aug 04, 2026 CVE-2026-14824
QSM question settings permit Contributor stored XSS
Quiz and Survey Master before 11.2.2 outputs a question setting into an unquoted HTML attribute without proper escaping. A Contributor can store a value that breaks out of the attribute and injects JavaScript, which executes for any user who views the affected quiz. The public advisory does not disclose the setting, save endpoint, request parameter, output attribute or rendering function.
11.2.2
CVE4.8
NVDPending
Jul 28, 2026 CVE-2026-14821
Quiz and Survey Master contributors can delete output templates
Quiz and Survey Master before 11.1.5 omits a capability check from its output-template deletion operation. Any authenticated Contributor can select and delete arbitrary QSM output templates, allowing a low-privilege account to disrupt or alter quiz and survey presentation. The WPScan CNA record does not disclose the endpoint, action, template identifier parameter or deletion function.
11.1.5
CVE2.7
NVDPending
Jul 27, 2026 CVE-2026-14820
Quiz and Survey Master credential checks enable account enumeration and brute force
Quiz and Survey Master before 11.1.3 exposes a front-end credential-check flow without rate limiting or useful audit controls and returns distinguishable responses for valid and invalid users. An unauthenticated attacker can use those response differences to enumerate usernames and repeatedly test passwords, potentially taking over an account whose credentials are guessed. The CNA record does not disclose the route, action, parameter names or validation function.
11.1.3
CVE5.3
NVDPending
Aug 14, 2025 CVE-2025-6790
Quiz and Survey Master (QSM): Cross-site request forgery
Quiz and Survey Master (QSM) is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.3
NVDPending