WordPress security by component
Quiz and Survey Master (QSM)
Plugin description
Quiz and Survey Master (QSM) is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 5.3.
Plugin slug:
quiz-and-survey-master-qsmLatest vulnerability
CVE-2026-14824: QSM question settings permit Contributor stored XSS
Quiz and Survey Master before 11.2.2 outputs a question setting into an unquoted HTML attribute without proper escaping. A Contributor can store a value that breaks out of the attribute and injects JavaScript, which executes for any user who views the affected quiz. The public advisory does not disclose the setting, save endpoint, request parameter, output attribute or rendering function.
| Safe version |
|
||
|---|---|---|---|
| Aug 04, 2026 |
CVE-2026-14824
QSM question settings permit Contributor stored XSS
Quiz and Survey Master before 11.2.2 outputs a question setting into an unquoted HTML attribute without proper escaping. A Contributor can store a value that breaks out of the attribute and injects JavaScript, which executes for any user who views the affected quiz. The public advisory does not disclose the setting, save endpoint, request parameter, output attribute or rendering function.
|
11.2.2 |
CVE4.8
NVDPending
|
| Jul 28, 2026 |
CVE-2026-14821
Quiz and Survey Master contributors can delete output templates
Quiz and Survey Master before 11.1.5 omits a capability check from its output-template deletion operation. Any authenticated Contributor can select and delete arbitrary QSM output templates, allowing a low-privilege account to disrupt or alter quiz and survey presentation. The WPScan CNA record does not disclose the endpoint, action, template identifier parameter or deletion function.
|
11.1.5 |
CVE2.7
NVDPending
|
| Jul 27, 2026 |
CVE-2026-14820
Quiz and Survey Master credential checks enable account enumeration and brute force
Quiz and Survey Master before 11.1.3 exposes a front-end credential-check flow without rate limiting or useful audit controls and returns distinguishable responses for valid and invalid users. An unauthenticated attacker can use those response differences to enumerate usernames and repeatedly test passwords, potentially taking over an account whose credentials are guessed. The CNA record does not disclose the route, action, parameter names or validation function.
|
11.1.3 |
CVE5.3
NVDPending
|
| Aug 14, 2025 |
CVE-2025-6790
Quiz and Survey Master (QSM): Cross-site request forgery
Quiz and Survey Master (QSM) is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.3
NVDPending
|