WordPress · Quiz/Survey Master · CVE-2026-9233
**Name of the Vulnerable Software and Affected Versions**
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker versions prior to 11.1.5
**Description**
An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Authenticated attackers with contributor-level access or higher can create, modify, and delete quiz output templates within the `mlw quiz output templates` database table. This flaw allows the storage of unsanitized HTML content, including arbitrary script tags.
**Recommendations**
Update the plugin to version 11.1.5 or later.