PT-2026-65392 · WordPress · Quiz/Survey Master
CVE-2026-14821
·
Published
2026-07-28
·
Updated
2026-07-28
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Quiz and Survey Master versions prior to 11.1.5
Description
The Quiz and Survey Master (QSM) WordPress plugin fails to perform a capability check before deleting output templates. This allows users with contributor-level access and above to delete arbitrary templates.
Recommendations
Update to version 11.1.5 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quiz/Survey Master