WordPress security by component
Quiz Master Next
Plugin description
Quiz Master Next creates and manages quizzes with questions, scoring, results, user participation, and configurable quiz settings.
Quiz Master Next (quiz-master-next) is a WordPress plugin with 48 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 9.3.
Plugin slug:
quiz-master-nextLatest vulnerability
CVE-2026-62140: Quiz And Survey Master exposes an unauthenticated object reference
Quiz And Survey Master through 11.2.5 has an insecure direct object reference reachable without authentication. The CNA vector requires no user interaction and rates confidentiality impact as low. The authoritative export does not identify the endpoint, action, object identifier, protected object, or data disclosed.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-62140
Quiz And Survey Master exposes an unauthenticated object reference
Quiz And Survey Master through 11.2.5 has an insecure direct object reference reachable without authentication. The CNA vector requires no user interaction and rates confidentiality impact as low. The authoritative export does not identify the endpoint, action, object identifier, protected object, or data disclosed.
|
11.2.6 |
CVE5.3
NVDPending
|
| Aug 19, 2026 |
CVE-2026-14826
QSM Contributors can read other users' quiz notification configuration
Quiz and Survey Master before 11.2.4 omits a per-object ownership check from REST routes that return quiz email-notification and results-page configuration. A Contributor can select a quiz created by another user and read its configuration, including notification-recipient email addresses.
|
11.2.4 |
CVE2.7
NVDPending
|
| Aug 19, 2026 |
CVE-2026-14825
QSM Contributors can modify other users' quiz text settings
Quiz and Survey Master before 11.2.4 omits a per-object ownership check before saving a quiz's front-end text settings. A Contributor can select a quiz created by another user and replace the text shown to visitors.
|
11.2.4 |
CVE2.7
NVDPending
|
| Aug 16, 2026 |
CVE-2026-15963
Quiz and Survey Master randon_category option permits SQL injection
Quiz and Survey Master through 11.2.1 incorporates the attacker-controlled randon_category quiz option into SQL without adequate escaping or preparation. A user holding the plugin's affected custom quiz-management access can append SQL and extract sensitive database information. The public.
|
11.2.4 |
CVE6.5
NVDPending
|
| Aug 16, 2026 |
CVE-2026-11780
Quiz and Survey Master question titles permit Contributor stored XSS
Quiz and Survey Master through 11.2.1 does not adequately sanitize and escape the Contributor-controlled question_title value. An attacker can store a script payload in quiz content, and it executes when a user views the affected quiz or management page. The public.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jul 23, 2026 |
CVE-2026-65454
Quiz And Survey Master: SQL injection
Quiz And Survey Master is affected by SQL injection. Exploitation requires an authenticated contributor account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 11.2.0.
|
11.2.1 |
CVE8.5
NVDPending
|
| Jul 16, 2026 |
CVE-2026-13767
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker: SQL injection
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker is affected by SQL injection. Exploitation requires an authenticated author account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 11.2.0.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jul 03, 2026 |
CVE-2026-9230
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker: A security weakness
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 11.1.4.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jun 27, 2026 |
CVE-2026-9233
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker: A security weakness
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 11.1.4.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jun 15, 2026 |
CVE-2026-48867
Quiz And Survey Master: Cross-site scripting
Quiz And Survey Master is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 11.1.2.
|
11.1.3 |
CVE7.1
NVDPending
|
| Jun 15, 2026 |
CVE-2026-40787
Quiz And Survey Master: Cross-site scripting
Quiz And Survey Master is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 11.0.0.
|
11.1.0 |
CVE7.1
NVDPending
|
| Jun 06, 2026 |
CVE-2026-6448
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker: SQL injection
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 11.1.2.
|
See mitigation notes |
CVE4.9
NVDPending
|
| Apr 17, 2026 |
CVE-2026-5797
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker: A security weakness
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 10.1.0.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Mar 23, 2026 |
CVE-2026-2412
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker: SQL injection
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker is affected by SQL injection. Exploitation requires an authenticated contributor account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 10.3.5.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Feb 20, 2026 |
CVE-2025-67987
Quiz And Survey Master: SQL injection
Quiz And Survey Master is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVDPending
|
| Feb 19, 2026 |
CVE-2026-25329
Quiz And Survey Master: A security weakness
Quiz And Survey Master is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Feb 19, 2026 |
CVE-2026-25324
Quiz And Survey Master: A security weakness
Quiz And Survey Master is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jan 22, 2026 |
CVE-2026-24358
Quiz And Survey Master: A security weakness
Quiz And Survey Master is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jan 06, 2026 |
CVE-2025-9637
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker: A security weakness
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jan 06, 2026 |
CVE-2025-9318
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker: SQL injection
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker is affected by SQL injection. Exploitation requires an authenticated subscriber account. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jan 06, 2026 |
CVE-2025-9294
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker: A security weakness
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Dec 09, 2025 |
CVE-2025-63054
Quiz And Survey Master: A security weakness
Quiz And Survey Master is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Aug 14, 2025 |
CVE-2025-55708
Quiz And Survey Master: SQL injection
Quiz And Survey Master is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVDPending
|
| Dec 13, 2024 |
CVE-2023-37984
Quiz And Survey Master: A security weakness
Quiz And Survey Master is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jun 14, 2024 |
CVE-2023-51507
Quiz And Survey Master: A security weakness
Quiz And Survey Master is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Apr 11, 2024 |
CVE-2024-27966
Quiz And Survey Master: Cross-site scripting
Quiz And Survey Master is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Mar 26, 2024 |
CVE-2023-28787
Quiz And Survey Master: SQL injection
Quiz And Survey Master is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.3
NVDPending
|
| Mar 16, 2024 |
CVE-2023-51521
Quiz And Survey Master: Cross-site request forgery
Quiz And Survey Master is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Nov 23, 2023 |
CVE-2023-47834
Quiz Master Next: Cross-site scripting
Quiz Master Next is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Nov 13, 2023 |
CVE-2023-26524
Quiz Master Next: Cross-site request forgery
Quiz Master Next is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Jun 09, 2023 |
CVE-2023-0292
Quiz And Survey Master: Cross-site request forgery
Quiz And Survey Master is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.1
|
| Jun 09, 2023 |
CVE-2023-0291
Quiz Master Next: A security weakness
Quiz Master Next is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.2
NVD9.1
|
| Feb 14, 2023 |
CVE-2022-46862
Quiz Master Next: Cross-site request forgery
Quiz Master Next is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Nov 18, 2022 |
CVE-2022-42883
Quiz Master Next: Sensitive information exposure
Quiz Master Next is affected by sensitive information exposure. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| Nov 18, 2022 |
CVE-2022-40698
Quiz Master Next: Cross-site scripting
Quiz Master Next is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD6.1
|
| Nov 18, 2022 |
CVE-2022-41652
Quiz Master Next: Privilege escalation or authentication bypass
Quiz Master Next is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE6.5
NVD9.8
|
| Nov 17, 2022 |
CVE-2021-36905
Quiz Master Next: Cross-site scripting
Quiz Master Next is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Nov 03, 2022 |
CVE-2021-36906
Quiz Master Next: Broken access control
Quiz Master Next is affected by broken access control. Exposure depends on how the affected operation is made reachable by the site. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
|
See mitigation notes |
CVE2.7
NVD8.8
|
| Oct 28, 2022 |
CVE-2021-36898
Quiz Master Next: SQL injection
Quiz Master Next is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.5
NVD7.2
|
| Oct 28, 2022 |
CVE-2021-36864
Quiz Master Next: Cross-site scripting
Quiz Master Next is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE3.4
NVD5.4
|
| Oct 28, 2022 |
CVE-2021-36863
Quiz Master Next: Cross-site scripting
Quiz Master Next is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Sep 30, 2022 |
CVE-2021-36865
Quiz Master Next: Broken access control
Quiz Master Next is affected by broken access control. Exposure depends on how the affected operation is made reachable by the site. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
|
See mitigation notes |
CVE3.8
NVD4.3
|
| Jan 17, 2022 |
CVE-2022-0182
Quiz Master Next: Cross-site scripting
Quiz Master Next is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD5.4
|
| Jan 17, 2022 |
CVE-2022-0181
Quiz Master Next: Cross-site scripting
Quiz Master Next is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Jan 17, 2022 |
CVE-2022-0180
Quiz Master Next: Cross-site request forgery
Quiz Master Next is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Aug 18, 2021 |
CVE-2021-20792
Quiz Master Next: Cross-site scripting
Quiz Master Next is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Dec 13, 2019 |
CVE-2019-17599
Quiz Master Next: Cross-site scripting
Quiz Master Next is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Mar 05, 2019 |
CVE-2019-9575
Quiz Master Next: Cross-site scripting
Quiz Master Next is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|