PatchSiren

Quiz and Survey Master CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Quiz and Survey Master CVE published 2026-08-19

CVE-2026-14825

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level access and above to modify the text settings of quizzes created by other users. This vulnerability has a CVSS score of 2.7 and is considered low-severity. However, it could still have a significant impact on the [truncated]

MEDIUM Quiz and Survey Master CVE published 2026-07-27

CVE-2026-14820

The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection. This vulnerability affects WordPr [truncated]