Quiz and Survey Master credential checks enable account enumeration and brute force
Quiz and Survey Master before 11.1.3 exposes a front-end credential-check flow without rate limiting or useful audit controls and returns distinguishable responses for valid and invalid users. An unauthenticated attacker can use those response differences to enumerate usernames and repeatedly test passwords, potentially taking over an account whose credentials are guessed. The CNA record does not disclose the route, action, parameter names or validation function.
- Component
- Quiz and Survey Master (QSM)
- Plugin slug
quiz-and-survey-master-qsm- Affected
- < 11.1.3
- Safe version
11.1.3- Published
- Jul 27, 2026
This CVE was published Jul 27, 2026 and is one of 3 known issues for this plugin.
Update, patch or deactivate.
Update Quiz and Survey Master to 11.1.3 or later. Review authentication logs for repeated credential checks, reset credentials for accounts showing suspicious activity and require multi-factor authentication where available.
A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.
Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.
Technical description
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N