PatchSiren

Quiz and Survey Master (QSM) CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Quiz and Survey Master (QSM) CVE published 2026-08-19

CVE-2026-14826

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 has a vulnerability allowing users with contributor-level access and above to read quiz configurations, including notification recipient addresses, created by other users. This is due to a lack of per-object ownership checks on REST routes for quiz email-notification and results-page configurations. The vulnerability has a CVSS score of 2.7 a [truncated]