The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level access and above to modify the text settings of quizzes created by other users. This vulnerability has a CVSS score of 2.7 and is considered low-severity. However, it could still have a significant impact on the [truncated]
MEDIUMQuiz and Survey MasterCVE published 2026-07-27
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection. This vulnerability affects WordPr [truncated]