PT-2026-78280 · WordPress · Quiz/Survey Master
CVE-2026-14826
·
Published
2026-08-19
·
Updated
2026-08-19
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Quiz and Survey Master (QSM) versions prior to 11.2.4
Description
The plugin fails to perform a per-object ownership check on REST routes that return the email-notification and results-page configuration of a quiz. This allows users with contributor-level access or higher to read the configuration of quizzes created by other users, which may include notification recipient addresses.
Recommendations
Update to version 11.2.4 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quiz/Survey Master